<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:patch="http://scap.nist.gov/schema/patch/0.1" xmlns:cvss="http://scap.nist.gov/schema/cvss-v2/0.2" xmlns:vuln="http://scap.nist.gov/schema/vulnerability/0.4" xmlns:cpe-lang="http://cpe.mitre.org/language/2.0" xmlns:scap-core="http://scap.nist.gov/schema/scap-core/0.1" xmlns="http://scap.nist.gov/schema/feed/vulnerability/2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" nvd_xml_version="2.0" pub_date="2019-10-10T04:46:28" xsi:schemaLocation="http://scap.nist.gov/schema/patch/0.1 https://scap.nist.gov/schema/nvd/patch_0.1.xsd http://scap.nist.gov/schema/feed/vulnerability/2.0 https://scap.nist.gov/schema/nvd/nvd-cve-feed_2.0.xsd http://scap.nist.gov/schema/scap-core/0.1 https://scap.nist.gov/schema/nvd/scap-core_0.1.xsd">
  <entry id="CVE-2007-0001">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::linux_kernel_2.6.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::linux_kernel_2.6.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0001</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:31.440-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.7</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9560" name="oval:org.mitre.oval:def:9560"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=223129" xml:lang="en">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=223129</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0085.html" xml:lang="en">RHSA-2007:0085</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22737" xml:lang="en">22737</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017705" xml:lang="en">1017705</vuln:reference>
    </vuln:references>
    <vuln:summary>The file watch implementation in the audit subsystem (auditctl -w) in the Red Hat Enterprise Linux (RHEL) 4 kernel 2.6.9 allows local users to cause a denial of service (kernel panic) by replacing a watched file, which does not cause the watch on the old inode to be dropped.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0002">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:libwpd:libwpd_library:0.8.2"/>
        <cpe-lang:fact-ref name="cpe:/a:libwpd:libwpd_library:0.8.6"/>
        <cpe-lang:fact-ref name="cpe:/a:libwpd:libwpd_library:0.8.7"/>
        <cpe-lang:fact-ref name="cpe:/a:libwpd:libwpd_library:0.8.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:libwpd:libwpd_library:0.8.2</vuln:product>
      <vuln:product>cpe:/a:libwpd:libwpd_library:0.8.6</vuln:product>
      <vuln:product>cpe:/a:libwpd:libwpd_library:0.8.7</vuln:product>
      <vuln:product>cpe:/a:libwpd:libwpd_library:0.8.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0002</vuln:cve-id>
    <vuln:published-datetime>2007-03-16T17:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:29:52.837-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11535" name="oval:org.mitre.oval:def:11535"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2805" xml:lang="en">FEDORA-2007-350</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=490" xml:lang="en">20070316 Multiple Vendor libwpd Multiple Buffer Overflow Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0007.html" xml:lang="en">SUSE-SA:2007:023</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200704-07.xml" xml:lang="en">GLSA-200704-07</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.399659" xml:lang="en">SSA-2007-085-02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=494122" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=494122</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102863-1" xml:lang="en">102863</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1268" xml:lang="en">DSA-1268</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1270" xml:lang="en">DSA-1270</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200704-12.xml" xml:lang="en">GLSA-200704-12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:063" xml:lang="en">MDKSA-2007:063</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:064" xml:lang="en">MDKSA-2007:064</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0055.html" xml:lang="en">RHSA-2007:0055</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/463033/100/0/threaded" xml:lang="en">20070316 rPSA-2007-0057-1 libwpd</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23006" xml:lang="en">23006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017789" xml:lang="en">1017789</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-437-1" xml:lang="en">USN-437-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0976" xml:lang="en">ADV-2007-0976</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1032" xml:lang="en">ADV-2007-1032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1339" xml:lang="en">ADV-2007-1339</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple heap-based buffer overflows in WordPerfect Document importer/exporter (libwpd) before 0.8.9 allow user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted WordPerfect file in which values to loop counters are not properly handled in the (1) WP3TablesGroup::_readContents and (2) WP5DefinitionGroup_DefineTablesSubGroup::WP5DefinitionGroup_DefineTablesSubGroup functions.  NOTE: the integer overflow has been split into CVE-2007-1466.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0003">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:andrew_morgan:linux_pam:0.99.7.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:andrew_morgan:linux_pam:0.99.7.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0003</vuln:cve-id>
    <vuln:published-datetime>2007-01-23T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:53.610-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_3_sr.html" xml:lang="en">SUSE-SR:2007:003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.redhat.com/archives/fedora-devel-list/2007-January/msg01271.html" xml:lang="en">[fedora-devel-list] 20070122 Re: rawhide report: 20070120 changes</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.redhat.com/archives/fedora-devel-list/2007-January/msg01277.html" xml:lang="en">[fedora-devel-list] 20070122 Re: rawhide report: 20070120 changes</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22204" xml:lang="en">22204</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0323" xml:lang="en">ADV-2007-0323</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31739" xml:lang="en">linuxpam-pamunix-security-bypass(31739)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/pam-list/2007-January/msg00017.html" xml:lang="en">[pam-list] 20070123 Linux-PAM 0.99.7.1 released</vuln:reference>
    </vuln:references>
    <vuln:summary>pam_unix.so in Linux-PAM 0.99.7.0 allows context-dependent attackers to log into accounts whose password hash, as stored in /etc/passwd or /etc/shadow, has only two characters.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0004">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0004</vuln:cve-id>
    <vuln:published-datetime>2007-09-18T15:17:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:16:46.527-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>1.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-09-19T15:34:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=199715" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=199715</vuln:reference>
    </vuln:references>
    <vuln:summary>The NFS client implementation in the kernel in Red Hat Enterprise Linux (RHEL) 3, when a filesystem is mounted with the noacl option, checks permissions for the open system call via vfs_permission (mode bits) data rather than an NFS ACCESS call to the server, which allows local client processes to obtain a false success status from open calls that the server would deny, and possibly obtain sensitive information about file permissions on the server, as demonstrated in a root_squash environment.  NOTE: it is uncertain whether any scenarios involving this issue cross privilege boundaries.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0005">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21:rc1"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21:rc2"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.1"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.2"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.3"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.4"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.5"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.6"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.21.7"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:omnikey.aaitg:omnikey_cardman_4040"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:omnikey.aaitg:omnikey_cardman_4040</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0005</vuln:cve-id>
    <vuln:published-datetime>2007-03-09T19:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:29:56.227-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11238" name="oval:org.mitre.oval:def:11238"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2787" xml:lang="en">FEDORA-2007-335</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2788" xml:lang="en">FEDORA-2007-336</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.21-rc3" xml:lang="en">http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.21-rc3</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1286" xml:lang="en">DSA-1286</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:078" xml:lang="en">MDKSA-2007:078</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0099.html" xml:lang="en">RHSA-2007:0099</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/462300/100/0/threaded" xml:lang="en">20070309 Buffer Overflow in Linux Drivers for Omnikey CardMan 4040 (CVE-2007-0005)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/471457" xml:lang="en">20070615 rPSA-2007-0124-1 kernel xen</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22870" xml:lang="en">22870</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-486-1" xml:lang="en">USN-486-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-489-1" xml:lang="en">USN-489-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0872" xml:lang="en">ADV-2007-0872</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32880" xml:lang="en">kernel-cardman4040drivers-bo(32880)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1035" xml:lang="en">https://issues.rpath.com/browse/RPL-1035</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in the (1) read and (2) write handlers in the Omnikey CardMan 4040 driver in the Linux kernel before 2.6.21-rc3 allow local users to gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0006">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.9:2.6.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.9:2.6.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0006</vuln:cve-id>
    <vuln:published-datetime>2007-02-06T14:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:31.703-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>1.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9829" name="oval:org.mitre.oval:def:9829"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugzilla.kernel.org/show_bug.cgi?id=7727" xml:lang="en">http://bugzilla.kernel.org/show_bug.cgi?id=7727</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:047" xml:lang="en">MDKSA-2007:047</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:060" xml:lang="en">MDKSA-2007:060</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_21_kernel.html" xml:lang="en">SUSE-SA:2007:021</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0085.html" xml:lang="en">RHSA-2007:0085</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0099.html" xml:lang="en">RHSA-2007:0099</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/471457" xml:lang="en">20070615 rPSA-2007-0124-1 kernel xen</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22539" xml:lang="en">22539</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-451-1" xml:lang="en">USN-451-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=227495" xml:lang="en">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=227495</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1097" xml:lang="en">https://issues.rpath.com/browse/RPL-1097</vuln:reference>
    </vuln:references>
    <vuln:summary>The key serial number collision avoidance code in the key_alloc_serial function in Linux kernel 2.6.9 up to 2.6.20 allows local users to cause a denial of service (crash) via vectors that trigger a null dereference, as originally reported as "spinlock CPU recursion."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0007">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gnucash:gnucash:2.0.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnucash:gnucash:2.0.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0007</vuln:cve-id>
    <vuln:published-datetime>2007-02-19T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:53.733-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2725" xml:lang="en">FEDORA-2007-256</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?group_id=192&amp;release_id=487446" xml:lang="en">http://sourceforge.net/project/shownotes.php?group_id=192&amp;release_id=487446</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:046" xml:lang="en">MDKSA-2007:046</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22610" xml:lang="en">22610</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0653" xml:lang="en">ADV-2007-0653</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=223233" xml:lang="en">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=223233</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32558" xml:lang="en">gnucash-symlink(32558)</vuln:reference>
    </vuln:references>
    <vuln:summary>gnucash 2.0.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on the (1) gnucash.trace, (2) qof.trace, and (3) qof.trace.[PID] temporary files.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0008">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9:rc"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0:preview_release"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.11.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.11.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.11.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:firefox:0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.6.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.7.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9:rc</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.10.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0:preview_release</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.4.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.11.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.11.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.11.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5:beta2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0008</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:29:58.257-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10502" name="oval:org.mitre.oval:def:10502"/>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc" xml:lang="en">20070202-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" xml:lang="en">20070301-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2709" xml:lang="en">FEDORA-2007-278</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2711" xml:lang="en">FEDORA-2007-279</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2713" xml:lang="en">FEDORA-2007-281</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2728" xml:lang="en">FEDORA-2007-293</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2747" xml:lang="en">FEDORA-2007-308</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2749" xml:lang="en">FEDORA-2007-309</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" xml:lang="en">HPSBUX02153</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=482" xml:lang="en">20070223 Mozilla Network Security Services SSLv2 Client Integer Underflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html" xml:lang="en">SUSE-SA:2007:019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2007-0077.html" xml:lang="en">RHSA-2007:0077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200703-18.xml" xml:lang="en">GLSA-200703-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131" xml:lang="en">SSA:2007-066-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.363947" xml:lang="en">SSA:2007-066-04</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.374851" xml:lang="en">SSA:2007-066-03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102856-1" xml:lang="en">102856</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102945-1" xml:lang="en">102945</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1336" xml:lang="en">DSA-1336</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200703-22.xml" xml:lang="en">GLSA-200703-22</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/377812" xml:lang="en">VU#377812</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:050" xml:lang="en">MDKSA-2007:050</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:052" xml:lang="en">MDKSA-2007:052</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2007/mfsa2007-06.html" xml:lang="en">http://www.mozilla.org/security/announce/2007/mfsa2007-06.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html" xml:lang="en">SUSE-SA:2007:022</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0078.html" xml:lang="en">RHSA-2007:0078</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0079.html" xml:lang="en">RHSA-2007:0079</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0097.html" xml:lang="en">RHSA-2007:0097</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0108.html" xml:lang="en">RHSA-2007:0108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461336/100/0/threaded" xml:lang="en">20070226 rPSA-2007-0040-1 firefox</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461809/100/0/threaded" xml:lang="en">20070303 rPSA-2007-0040-3 firefox thunderbird</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22694" xml:lang="en">22694</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/64758" xml:lang="en">64758</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017696" xml:lang="en">1017696</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-428-1" xml:lang="en">USN-428-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-431-1" xml:lang="en">USN-431-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0718" xml:lang="en">ADV-2007-0718</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0719" xml:lang="en">ADV-2007-0719</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1165" xml:lang="en">ADV-2007-1165</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2141" xml:lang="en">ADV-2007-2141</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=364319" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=364319</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32666" xml:lang="en">nss-mastersecret-bo(32666)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1081" xml:lang="en">https://issues.rpath.com/browse/RPL-1081</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1103" xml:lang="en">https://issues.rpath.com/browse/RPL-1103</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer underflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, SeaMonkey before 1.0.8, Thunderbird before 1.5.0.10, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via a crafted SSLv2 server message containing a public key that is too short to encrypt the "Master Secret", which results in a heap-based overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0009">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:-"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.7.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.7.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.10.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.11.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.11.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.11.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:network_security_services:3.11.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:-"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:-"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7:-"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7:rc"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0:-"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0:rc"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.1:alpha1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.1:alpha2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5:-"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:5.10"/>
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:6.06::~~lts~~~"/>
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:6.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:firefox:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:-</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.2.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.3.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.3.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.4.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.4.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.4.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.6.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.7.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.7.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.7.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.7.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.7.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.9.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.9.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.9.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.9.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.9.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.10.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.10.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.11.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.11.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.11.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:network_security_services:3.11.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:-</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:-</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7:-</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7:rc</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0:-</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0:rc</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.1:alpha1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.1:alpha2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5:-</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5:beta1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5:beta2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5:rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.9</vuln:product>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:5.10</vuln:product>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:6.06::~~lts~~~</vuln:product>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:6.10</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.1</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0009</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-10-09T18:51:51.787-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10174" name="oval:org.mitre.oval:def:10174"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc" xml:lang="en">20070202-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" xml:lang="en">20070301-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2709" xml:lang="en">FEDORA-2007-278</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2711" xml:lang="en">FEDORA-2007-279</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2747" xml:lang="en">FEDORA-2007-308</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2749" xml:lang="en">FEDORA-2007-309</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" xml:lang="en">HPSBUX02153</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=483" xml:lang="en">20070223 Mozilla Network Security Services SSLv2 Server Stack Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html" xml:lang="en">SUSE-SA:2007:019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2007-0077.html" xml:lang="en">RHSA-2007:0077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200703-18.xml" xml:lang="en">GLSA-200703-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131" xml:lang="en">SSA:2007-066-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.363947" xml:lang="en">SSA:2007-066-04</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.374851" xml:lang="en">SSA:2007-066-03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102856-1" xml:lang="en">102856</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102945-1" xml:lang="en">102945</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1336" xml:lang="en">DSA-1336</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200703-22.xml" xml:lang="en">GLSA-200703-22</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/592796" xml:lang="en">VU#592796</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:050" xml:lang="en">MDKSA-2007:050</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:052" xml:lang="en">MDKSA-2007:052</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2007/mfsa2007-06.html" xml:lang="en">http://www.mozilla.org/security/announce/2007/mfsa2007-06.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html" xml:lang="en">SUSE-SA:2007:022</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0078.html" xml:lang="en">RHSA-2007:0078</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0079.html" xml:lang="en">RHSA-2007:0079</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0097.html" xml:lang="en">RHSA-2007:0097</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0108.html" xml:lang="en">RHSA-2007:0108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461336/100/0/threaded" xml:lang="en">20070226 rPSA-2007-0040-1 firefox</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461809/100/0/threaded" xml:lang="en">20070303 rPSA-2007-0040-3 firefox thunderbird</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/64758" xml:lang="en">64758</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017696" xml:lang="en">1017696</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-428-1" xml:lang="en">USN-428-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-431-1" xml:lang="en">USN-431-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0718" xml:lang="en">ADV-2007-0718</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0719" xml:lang="en">ADV-2007-0719</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1165" xml:lang="en">ADV-2007-1165</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2141" xml:lang="en">ADV-2007-2141</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=364323" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=364323</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32663" xml:lang="en">nss-clientmasterkey-bo(32663)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1081" xml:lang="en">https://issues.rpath.com/browse/RPL-1081</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1103" xml:lang="en">https://issues.rpath.com/browse/RPL-1103</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, SeaMonkey before 1.0.8, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via invalid "Client Master Key" length values.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0010">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:the_gimp_team:gimp_toolkit:2.4.12"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:the_gimp_team:gimp_toolkit:2.4.12</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0010</vuln:cve-id>
    <vuln:published-datetime>2007-01-24T14:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:32.017-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10325" name="oval:org.mitre.oval:def:10325"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017552" xml:lang="en">1017552</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:039" xml:lang="en">MDKSA-2007:039</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_02_sr.html" xml:lang="en">SUSE-SR:2007:002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0019.html" xml:lang="en">RHSA-2007:0019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22209" xml:lang="en">22209</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-415-1" xml:lang="en">USN-415-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0331" xml:lang="en">ADV-2007-0331</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=218932" xml:lang="en">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=218932</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-984" xml:lang="en">https://issues.rpath.com/browse/RPL-984</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="https://www.debian.org/security/2007/dsa-1256" xml:lang="en">DSA-1256</vuln:reference>
    </vuln:references>
    <vuln:summary>The GdkPixbufLoader function in GIMP ToolKit (GTK+) in GTK 2 (gtk2) before 2.4.13 allows context-dependent attackers to cause a denial of service (crash) via a malformed image file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0011">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:citrix:access_gateway:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:citrix:access_gateway:4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:citrix:access_gateway:4.5::advanced"/>
        <cpe-lang:fact-ref name="cpe:/a:citrix:access_gateway:4.5::standard"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:citrix:access_gateway:4.0</vuln:product>
      <vuln:product>cpe:/a:citrix:access_gateway:4.2</vuln:product>
      <vuln:product>cpe:/a:citrix:access_gateway:4.5::advanced</vuln:product>
      <vuln:product>cpe:/a:citrix:access_gateway:4.5::standard</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0011</vuln:cve-id>
    <vuln:published-datetime>2007-11-05T12:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:30:16.790-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1018435" xml:lang="en">1018435</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.citrix.com/article/CTX112803" xml:lang="en">http://support.citrix.com/article/CTX112803</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.citrix.com/article/CTX113814" xml:lang="en">http://support.citrix.com/article/CTX113814</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/482626/100/100/threaded" xml:lang="en">20071022 Corsaire Security Advisory - Citrix Access Gateway session ID disclosure issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/24975" xml:lang="en">24975</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2583" xml:lang="en">ADV-2007-2583</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/35510" xml:lang="en">citrix-access-unspeci-information-disclosure(35510)</vuln:reference>
    </vuln:references>
    <vuln:summary>The web portal interface in Citrix Access Gateway (aka Citrix Advanced Access Control) before Advanced Edition 4.5 HF1 places a session ID in the URL, which allows context-dependent attackers to hijack sessions by reading "residual information", including the a referer log, browser history, or browser cache.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0012">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update13"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update10</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update13</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update8</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0012</vuln:cve-id>
    <vuln:published-datetime>2008-01-09T18:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:30:17.367-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/3527" xml:lang="en">3527</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/485942/100/0/threaded" xml:lang="en">20080108 Corsaire Security Advisory: Sun J2RE DoS issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27185" xml:lang="en">27185</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/39549" xml:lang="en">sun-java-jpiexp32-dos(39549)</vuln:reference>
    </vuln:references>
    <vuln:summary>Sun JRE 5.0 before update 14 allows remote attackers to cause a denial of service (Internet Explorer crash) via an object tag with an encoded applet and an undefined name attribute, which triggers a NULL pointer dereference in jpiexp32.dll when the applet is decoded and passed to the JVM.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0014">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sun:chainkey_java_code_protection"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:chainkey_java_code_protection</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0014</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:30:17.680-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.4</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-310"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456712/100/0/threaded" xml:lang="en">20070112 Corsaire Security Advisory: ChainKey Java Code Protection Bypass issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456734/100/0/threaded" xml:lang="en">20070112 Re: Corsaire Security Advisory: ChainKey Java Code Protection Bypass issue</vuln:reference>
    </vuln:references>
    <vuln:summary>ChainKey Java Code Protection allows attackers to decompile Java class files via a Java class loader with a modified defineClass method that saves the bytecode to a file before it is passed to the JVM.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0015">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:quicktime:7.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0015</vuln:cve-id>
    <vuln:published-datetime>2007-01-01T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:55.503-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=304989" xml:lang="en">http://docs.info.apple.com/article.html?artnum=304989</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://isc.sans.org/diary.html?storyid=2094" xml:lang="en">http://isc.sans.org/diary.html?storyid=2094</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://landonf.bikemonkey.org/code/macosx/MOAB_Day_1.20070102060815.15950.zadder.local.html" xml:lang="en">http://landonf.bikemonkey.org/code/macosx/MOAB_Day_1.20070102060815.15950.zadder.local.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Jan/msg00000.html" xml:lang="en">APPLE-SA-2007-01-23</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-01-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-01-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017461" xml:lang="en">1017461</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/442497" xml:lang="en">VU#442497</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21829" xml:lang="en">21829</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-005A.html" xml:lang="en">TA07-005A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0001" xml:lang="en">ADV-2007-0001</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31203" xml:lang="en">quicktime-rtsp-url-bo(31203)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3064" xml:lang="en">3064</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Apple QuickTime 7.1.3 allows remote attackers to execute arbitrary code via a long rtsp:// URI.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0016">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:netfarer:movieplay:4.76"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:netfarer:movieplay:4.76</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0016</vuln:cve-id>
    <vuln:published-datetime>2007-01-02T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:32.080-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21840" xml:lang="en">21840</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/4051" xml:lang="en">4051</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in MoviePlay 4.76 allows remote attackers to execute arbitrary code via a long filename in a LST file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0017">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.8.2"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.8.4"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.8.4a"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.8.5"/>
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.8.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.7.0</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.7.1</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.7.2</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.8.0</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.8.1</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.8.2</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.8.4</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.8.4a</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.8.5</vuln:product>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.8.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0017</vuln:cve-id>
    <vuln:published-datetime>2007-01-02T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:32.157-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14313" name="oval:org.mitre.oval:def:14313"/>
    <vuln:cwe id="CWE-134"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://applefun.blogspot.com/2007/01/moab-02-01-2007-vlc-media-player-udp.html" xml:lang="en">http://applefun.blogspot.com/2007/01/moab-02-01-2007-vlc-media-player-udp.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://landonf.bikemonkey.org/code/macosx/MOAB_Day_2.20070103045559.6753.timor.html" xml:lang="en">http://landonf.bikemonkey.org/code/macosx/MOAB_Day_2.20070103045559.6753.timor.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-02-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-02-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200701-24.xml" xml:lang="en">GLSA-200701-24</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017464" xml:lang="en">1017464</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://trac.videolan.org/vlc/changeset/18481" xml:lang="en">http://trac.videolan.org/vlc/changeset/18481</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1252" xml:lang="en">DSA-1252</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_13_xine.html" xml:lang="en">SUSE-SA:2007:013</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21852" xml:lang="en">21852</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.via.ecp.fr/via/ml/vlc-devel/2007-01/msg00005.html" xml:lang="en">[vlc-devel] 20070102 Security hole in VLC media player for Mac...</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.videolan.org/patches/vlc-0.8.6-MOAB-02-01-2007.patch" xml:lang="en">http://www.videolan.org/patches/vlc-0.8.6-MOAB-02-01-2007.patch</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.videolan.org/sa0701.html" xml:lang="en">http://www.videolan.org/sa0701.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0026" xml:lang="en">ADV-2007-0026</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31226" xml:lang="en">vlcmediaplayer-udp-format-string(31226)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple format string vulnerabilities in (1) the cdio_log_handler function in modules/access/cdda/access.c in the CDDA (libcdda_plugin) plugin, and the (2) cdio_log_handler and (3) vcd_log_handler functions in modules/access/vcdx/access.c in the VCDX (libvcdx_plugin) plugin, in VideoLAN VLC 0.7.0 through 0.8.6 allow user-assisted remote attackers to execute arbitrary code via format string specifiers in an invalid URI, as demonstrated by a udp://-- URI in an M3U file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0018">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:altdo:convert_mp3_master:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:altdo:mp3_record_and_edit_audio_master:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:americanshareware:mp3_wav_converter:3.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:audio_edit_magic:audio_edit_magic:9.2.3_389"/>
        <cpe-lang:fact-ref name="cpe:/a:bearshare:bearshare:6.0.2.26789"/>
        <cpe-lang:fact-ref name="cpe:/a:cdburnerxp:cdburnerxp_pro:3.0.116"/>
        <cpe-lang:fact-ref name="cpe:/a:cheetahburner:cheetah_cd_burner:3.56"/>
        <cpe-lang:fact-ref name="cpe:/a:cheetahburner:cheetah_dvd_burner:1.79"/>
        <cpe-lang:fact-ref name="cpe:/a:code-it_softare:abasic_editor:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:code-it_softare:wave_mp3_editor:10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:dandans_digital_media_products:easy_audio_editor:7.4"/>
        <cpe-lang:fact-ref name="cpe:/a:dandans_digital_media_products:full_audio_converter:4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:dandans_digital_media_products:music_editing_master:5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:dandans_digital_media_products:visual_video_converter:4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:digital_borneo:audio_mixer_and_editor:1.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:easy_ringtone_maker:easy_ringtone_maker:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:expstudio:audio_editor:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:iaudiosoft.com:absolute_mp3_splitter:2.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:iaudiosoft.com:absolute_sound_recorder:3.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:iaudiosoft.com:absolute_video_to_audio_converter:2.7.9"/>
        <cpe-lang:fact-ref name="cpe:/a:imesh.com:imesh:7.0.2.26789"/>
        <cpe-lang:fact-ref name="cpe:/a:j_hepple_products:fx_audio_concat:1.2.0_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:j_hepple_products:fx_audio_editor:4.7.11"/>
        <cpe-lang:fact-ref name="cpe:/a:j_hepple_products:fx_audio_tools:7.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:j_hepple_products:fx_magic_music:5.7.7"/>
        <cpe-lang:fact-ref name="cpe:/a:j_hepple_products:fx_movie_joiner:6.2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:j_hepple_products:fx_movie_joiner_and_splitter:6.2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:j_hepple_products:fx_movie_splitter:6.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:j_hepple_products:fx_new_sound:5.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:j_hepple_products:fx_video_converter:7.51.21"/>
        <cpe-lang:fact-ref name="cpe:/a:joshua_mediasoft:audio_convertor_plus:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:joshua_mediasoft:video_converter_plus:3.01"/>
        <cpe-lang:fact-ref name="cpe:/a:magicvideosoftare:magic_audio_converter:8.2.6_build_719"/>
        <cpe-lang:fact-ref name="cpe:/a:magicvideosoftare:magic_audio_recorder:5.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:magicvideosoftare:magic_music_editor:5.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mcfunsoft:audio_editor:6.3.3_build_489"/>
        <cpe-lang:fact-ref name="cpe:/a:mcfunsoft:audio_recorder_for_free:6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mcfunsoft:audio_studio:6.6.3_build_479"/>
        <cpe-lang:fact-ref name="cpe:/a:mcfunsoft:ipod_audio_studio:6.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mcfunsoft:ipod_music_converter:5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mcfunsoft:recording_to_ipod_solution:5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediatox:aurora_media_workshop:3.3.25"/>
        <cpe-lang:fact-ref name="cpe:/a:movavi:chiliburner:2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:movavi:convertmovie:4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:movavi:dvd_to_ipod:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:movavi:splitmovie:1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:movavi:suite:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:movavi:videomessage:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mp3-soft:mp3_normalizer:1.03"/>
        <cpe-lang:fact-ref name="cpe:/a:mystik_media_products:audioedit_deluxe:4.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mystik_media_products:blaze_media_pro:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mystik_media_products:blaze_mediaconvert:3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mystik_media_products:contextconvert_pro:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:nctsoft_products:nctaudioeditor:2.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:nctsoft_products:nctaudiofile2"/>
        <cpe-lang:fact-ref name="cpe:/a:nctsoft_products:nctaudiostudio:2.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:nctsoft_products:nctdialogicvoice:2.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:nextlevel_systems:audio_editor_gold:9.2.5_build_424"/>
        <cpe-lang:fact-ref name="cpe:/a:nextlevel_systems:audio_studio_gold:7.0.1.1_build_500"/>
        <cpe-lang:fact-ref name="cpe:/a:quikscribe:quikscribe_player:5.022.05"/>
        <cpe-lang:fact-ref name="cpe:/a:quikscribe:quikscribe_recorder:5.021.29"/>
        <cpe-lang:fact-ref name="cpe:/a:recordnrip:recordnrip:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:rmbsoft:audioconvert:3.1.0.125"/>
        <cpe-lang:fact-ref name="cpe:/a:rmbsoft:soundedit_pro:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:roemer_software:easy_hi-q_converter:1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:roemer_software:easy_hi-q_recorder:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:roemer_software:free_hi-q_recorder:1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:sienzo:digital_music_mentor:2.6.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:smart_media_systems:power_audio_editor:11.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:softdiv_softare:dexster:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:softdiv_softare:ivideomax:3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:softdiv_softare:mp3_to_wav_converter:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:softdiv_softare:snosh:1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:softdiv_softare:videozilla:2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:virtual_cd:virtual_cd:6.0.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:virtual_cd:virtual_cd:7.1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:virtual_cd:virtual_cd:8.0.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:virtual_cd:virtual_cd_file_server:7.1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:xrlly_software:arial_audio_converter:2.3.40"/>
        <cpe-lang:fact-ref name="cpe:/a:xrlly_software:arial_sound_recorder:1.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:xrlly_software:text_to_speech_maker:1.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:xwaver.com:magic_audio_editor_pro:10.3.1_build_476"/>
        <cpe-lang:fact-ref name="cpe:/a:xwaver.com:magic_music_studio_pro:7.0.2.1_build_500"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:altdo:convert_mp3_master:1.1</vuln:product>
      <vuln:product>cpe:/a:altdo:mp3_record_and_edit_audio_master:1.2</vuln:product>
      <vuln:product>cpe:/a:americanshareware:mp3_wav_converter:3.1.8</vuln:product>
      <vuln:product>cpe:/a:audio_edit_magic:audio_edit_magic:9.2.3_389</vuln:product>
      <vuln:product>cpe:/a:bearshare:bearshare:6.0.2.26789</vuln:product>
      <vuln:product>cpe:/a:cdburnerxp:cdburnerxp_pro:3.0.116</vuln:product>
      <vuln:product>cpe:/a:cheetahburner:cheetah_cd_burner:3.56</vuln:product>
      <vuln:product>cpe:/a:cheetahburner:cheetah_dvd_burner:1.79</vuln:product>
      <vuln:product>cpe:/a:code-it_softare:abasic_editor:10.1</vuln:product>
      <vuln:product>cpe:/a:code-it_softare:wave_mp3_editor:10.1</vuln:product>
      <vuln:product>cpe:/a:dandans_digital_media_products:easy_audio_editor:7.4</vuln:product>
      <vuln:product>cpe:/a:dandans_digital_media_products:full_audio_converter:4.2</vuln:product>
      <vuln:product>cpe:/a:dandans_digital_media_products:music_editing_master:5.2</vuln:product>
      <vuln:product>cpe:/a:dandans_digital_media_products:visual_video_converter:4.4</vuln:product>
      <vuln:product>cpe:/a:digital_borneo:audio_mixer_and_editor:1.1.0</vuln:product>
      <vuln:product>cpe:/a:easy_ringtone_maker:easy_ringtone_maker:2.0.5</vuln:product>
      <vuln:product>cpe:/a:expstudio:audio_editor:4.0.2</vuln:product>
      <vuln:product>cpe:/a:iaudiosoft.com:absolute_mp3_splitter:2.5.4</vuln:product>
      <vuln:product>cpe:/a:iaudiosoft.com:absolute_sound_recorder:3.4.5</vuln:product>
      <vuln:product>cpe:/a:iaudiosoft.com:absolute_video_to_audio_converter:2.7.9</vuln:product>
      <vuln:product>cpe:/a:imesh.com:imesh:7.0.2.26789</vuln:product>
      <vuln:product>cpe:/a:j_hepple_products:fx_audio_concat:1.2.0_beta</vuln:product>
      <vuln:product>cpe:/a:j_hepple_products:fx_audio_editor:4.7.11</vuln:product>
      <vuln:product>cpe:/a:j_hepple_products:fx_audio_tools:7.3.4</vuln:product>
      <vuln:product>cpe:/a:j_hepple_products:fx_magic_music:5.7.7</vuln:product>
      <vuln:product>cpe:/a:j_hepple_products:fx_movie_joiner:6.2.8</vuln:product>
      <vuln:product>cpe:/a:j_hepple_products:fx_movie_joiner_and_splitter:6.2.8</vuln:product>
      <vuln:product>cpe:/a:j_hepple_products:fx_movie_splitter:6.4.7</vuln:product>
      <vuln:product>cpe:/a:j_hepple_products:fx_new_sound:5.1.1</vuln:product>
      <vuln:product>cpe:/a:j_hepple_products:fx_video_converter:7.51.21</vuln:product>
      <vuln:product>cpe:/a:joshua_mediasoft:audio_convertor_plus:2.2</vuln:product>
      <vuln:product>cpe:/a:joshua_mediasoft:video_converter_plus:3.01</vuln:product>
      <vuln:product>cpe:/a:magicvideosoftare:magic_audio_converter:8.2.6_build_719</vuln:product>
      <vuln:product>cpe:/a:magicvideosoftare:magic_audio_recorder:5.3.7</vuln:product>
      <vuln:product>cpe:/a:magicvideosoftare:magic_music_editor:5.2.2</vuln:product>
      <vuln:product>cpe:/a:mcfunsoft:audio_editor:6.3.3_build_489</vuln:product>
      <vuln:product>cpe:/a:mcfunsoft:audio_recorder_for_free:6.1</vuln:product>
      <vuln:product>cpe:/a:mcfunsoft:audio_studio:6.6.3_build_479</vuln:product>
      <vuln:product>cpe:/a:mcfunsoft:ipod_audio_studio:6.2.4</vuln:product>
      <vuln:product>cpe:/a:mcfunsoft:ipod_music_converter:5.1</vuln:product>
      <vuln:product>cpe:/a:mcfunsoft:recording_to_ipod_solution:5.1</vuln:product>
      <vuln:product>cpe:/a:mediatox:aurora_media_workshop:3.3.25</vuln:product>
      <vuln:product>cpe:/a:movavi:chiliburner:2.3</vuln:product>
      <vuln:product>cpe:/a:movavi:convertmovie:4.4</vuln:product>
      <vuln:product>cpe:/a:movavi:dvd_to_ipod:1.0</vuln:product>
      <vuln:product>cpe:/a:movavi:splitmovie:1.4</vuln:product>
      <vuln:product>cpe:/a:movavi:suite:3.5</vuln:product>
      <vuln:product>cpe:/a:movavi:videomessage:1.0</vuln:product>
      <vuln:product>cpe:/a:mp3-soft:mp3_normalizer:1.03</vuln:product>
      <vuln:product>cpe:/a:mystik_media_products:audioedit_deluxe:4.10</vuln:product>
      <vuln:product>cpe:/a:mystik_media_products:blaze_media_pro:7.0</vuln:product>
      <vuln:product>cpe:/a:mystik_media_products:blaze_mediaconvert:3.4</vuln:product>
      <vuln:product>cpe:/a:mystik_media_products:contextconvert_pro:3.1</vuln:product>
      <vuln:product>cpe:/a:nctsoft_products:nctaudioeditor:2.7.1</vuln:product>
      <vuln:product>cpe:/a:nctsoft_products:nctaudiofile2</vuln:product>
      <vuln:product>cpe:/a:nctsoft_products:nctaudiostudio:2.7.1</vuln:product>
      <vuln:product>cpe:/a:nctsoft_products:nctdialogicvoice:2.7.1</vuln:product>
      <vuln:product>cpe:/a:nextlevel_systems:audio_editor_gold:9.2.5_build_424</vuln:product>
      <vuln:product>cpe:/a:nextlevel_systems:audio_studio_gold:7.0.1.1_build_500</vuln:product>
      <vuln:product>cpe:/a:quikscribe:quikscribe_player:5.022.05</vuln:product>
      <vuln:product>cpe:/a:quikscribe:quikscribe_recorder:5.021.29</vuln:product>
      <vuln:product>cpe:/a:recordnrip:recordnrip:1.0</vuln:product>
      <vuln:product>cpe:/a:rmbsoft:audioconvert:3.1.0.125</vuln:product>
      <vuln:product>cpe:/a:rmbsoft:soundedit_pro:2.1</vuln:product>
      <vuln:product>cpe:/a:roemer_software:easy_hi-q_converter:1.7</vuln:product>
      <vuln:product>cpe:/a:roemer_software:easy_hi-q_recorder:2.0</vuln:product>
      <vuln:product>cpe:/a:roemer_software:free_hi-q_recorder:1.9</vuln:product>
      <vuln:product>cpe:/a:sienzo:digital_music_mentor:2.6.0.3</vuln:product>
      <vuln:product>cpe:/a:smart_media_systems:power_audio_editor:11.0.1</vuln:product>
      <vuln:product>cpe:/a:softdiv_softare:dexster:3.0</vuln:product>
      <vuln:product>cpe:/a:softdiv_softare:ivideomax:3.9</vuln:product>
      <vuln:product>cpe:/a:softdiv_softare:mp3_to_wav_converter:3.0</vuln:product>
      <vuln:product>cpe:/a:softdiv_softare:snosh:1.4</vuln:product>
      <vuln:product>cpe:/a:softdiv_softare:videozilla:2.5</vuln:product>
      <vuln:product>cpe:/a:virtual_cd:virtual_cd:6.0.0.7</vuln:product>
      <vuln:product>cpe:/a:virtual_cd:virtual_cd:7.1.0.2</vuln:product>
      <vuln:product>cpe:/a:virtual_cd:virtual_cd:8.0.0.6</vuln:product>
      <vuln:product>cpe:/a:virtual_cd:virtual_cd_file_server:7.1.0.3</vuln:product>
      <vuln:product>cpe:/a:xrlly_software:arial_audio_converter:2.3.40</vuln:product>
      <vuln:product>cpe:/a:xrlly_software:arial_sound_recorder:1.4.3</vuln:product>
      <vuln:product>cpe:/a:xrlly_software:text_to_speech_maker:1.3.8</vuln:product>
      <vuln:product>cpe:/a:xwaver.com:magic_audio_editor_pro:10.3.1_build_476</vuln:product>
      <vuln:product>cpe:/a:xwaver.com:magic_music_studio_pro:7.0.2.1_build_500</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0018</vuln:cve-id>
    <vuln:published-datetime>2007-01-24T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:30:18.023-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/292713" xml:lang="en">VU#292713</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457936/100/200/threaded" xml:lang="en">20070124 Secunia Research: NCTsoft Products NCTAudioFile2 ActiveX ControlBuffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457940/100/200/threaded" xml:lang="en">20070124 Secunia Research: Sienzo Digital Music Mentor NCTAudioFile2ActiveX Control Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457965/100/200/threaded" xml:lang="en">20070124 Re: Secunia Research: NCTsoft Products NCTAudioFile2 ActiveXControl Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22196" xml:lang="en">22196</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23892" xml:lang="en">23892</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0310" xml:lang="en">ADV-2007-0310</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31707" xml:lang="en">nctaudiofile2-multiple-bo(31707)</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple products, allows remote attackers to execute arbitrary code via a long argument to the SetFormatLikeSample function. NOTE: the products include (1) NCTsoft NCTAudioStudio, NCTAudioEditor, and NCTDialogicVoice; (2) Magic Audio Recorder, Music Editor, and Audio Converter; (3) Aurora Media Workshop; DB Audio Mixer And Editor; (4) J. Hepple Products including Fx Audio Editor and others; (5) EXPStudio Audio Editor; (6) iMesh; (7) Quikscribe; (8) RMBSoft AudioConvert and SoundEdit Pro 2.1; (9) CDBurnerXP; (10) Code-it Software Wave MP3 Editor and aBasic Editor; (11) Movavi VideoMessage, DVD to iPod, and others; (12) SoftDiv Software Dexster, iVideoMAX, and others; (13) Sienzo Digital Music Mentor (DMM); (14) MP3 Normalizer; (15) Roemer Software FREE and Easy Hi-Q Recorder, and Easy Hi-Q Converter; (16) Audio Edit Magic; (17) Joshua Video and Audio Converter; (18) Virtual CD; (19) Cheetah CD and DVD Burner; (20) Mystik Media AudioEdit Deluxe, Blaze Media, and others; (21) Power Audio Editor; (22) DanDans Digital Media Full Audio Converter, Music Editing Master, and others; (23) Xrlly Software Text to Speech Makerand Arial Sound Recorder / Audio Converter; (24) Absolute Sound Recorder, Video to Audio Converter, and MP3 Splitter; (25) Easy Ringtone Maker; (26) RecordNRip; (27) McFunSoft iPod Audio Studio, Audio Recorder for Free, and others; (28) MP3 WAV Converter; (29) BearShare 6.0.2.26789; and (30) Oracle Siebel SimBuilder and CRM 7.x.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0019">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:maxum_development_corporation:rumpus_ftp_server:5.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:maxum_development_corporation:rumpus_ftp_server:5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0019</vuln:cve-id>
    <vuln:published-datetime>2007-01-19T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:54.437-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-18-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-18-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31594" xml:lang="en">rumpus-ftp-http-bo(31594)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple heap-based buffer overflows in rumpusd in Rumpus 5.1 and earlier (1) allow remote authenticated users to execute arbitrary code via a long LIST command and other unspecified requests to the FTP service, and (2) allow remote attackers to execute arbitrary code via unspecified requests to the HTTP service.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0020">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:panic_transmit:panic_transmit:3.5.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:panic_transmit:panic_transmit:3.5.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0020</vuln:cve-id>
    <vuln:published-datetime>2007-01-23T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:55.550-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-19-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-19-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22145" xml:lang="en">22145</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0273" xml:lang="en">ADV-2007-0273</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31673" xml:lang="en">transmit-url-handler-bo(31673)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3160" xml:lang="en">3160</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in the SFTP protocol handler for Panic Transmit (Transmit.app) up to 3.5.5 allows remote attackers to execute arbitrary code via a long ftps:// URL.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0021">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:ichat:3.1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:ichat:3.1.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0021</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:54.547-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305102" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305102</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Feb/msg00000.html" xml:lang="en">APPLE-SA-2007-02-15</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-20-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-20-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/794752" xml:lang="en">VU#794752</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22146" xml:lang="en">22146</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017661" xml:lang="en">1017661</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-047A.html" xml:lang="en">TA07-047A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0274" xml:lang="en">ADV-2007-0274</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31679" xml:lang="en">ichat-aim-format-string(31679)</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in Apple iChat 3.1.6 allows remote attackers to cause a denial of service (null pointer dereference and application crash) and possibly execute arbitrary code via format string specifiers in an aim:// URI.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0022">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0022</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:54.610-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305391" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305391</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" xml:lang="en">APPLE-SA-2007-04-19</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-21-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-21-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22148" xml:lang="en">22148</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017941" xml:lang="en">1017941</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" xml:lang="en">TA07-109A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0074" xml:lang="en">ADV-2007-0074</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1470" xml:lang="en">ADV-2007-1470</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31677" xml:lang="en">macos-writeconfig-privilege-escalation(31677)</vuln:reference>
    </vuln:references>
    <vuln:summary>Untrusted search path vulnerability in writeconfig in Apple Mac OS X 10.4.8 allows local users to gain privileges via a modified PATH that points to a malicious launchctl program.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0023">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0023</vuln:cve-id>
    <vuln:published-datetime>2007-01-23T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:54.670-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305102" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305102</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Feb/msg00000.html" xml:lang="en">APPLE-SA-2007-02-15</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-22-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-22-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017542" xml:lang="en">1017542</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/315856" xml:lang="en">VU#315856</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22188" xml:lang="en">22188</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-047A.html" xml:lang="en">TA07-047A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0074" xml:lang="en">ADV-2007-0074</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31676" xml:lang="en">macos-inputmanager-privilege-escalation(31676)</vuln:reference>
    </vuln:references>
    <vuln:summary>The CFUserNotificationSendRequest function in UserNotificationCenter.app in Apple Mac OS X 10.4.8, when used in combination with diskutil, allows local users to gain privileges via a malicious InputManager in Library/InputManagers in a user's home directory, which is executed when Cocoa applications attempt to notify the user.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0024">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.01:sp4"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:::64-bit"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:::itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1::itanium"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.01:sp4</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:7.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0024</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:30:32.743-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1058" name="oval:org.mitre.oval:def:1058"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=462" xml:lang="en">20070109 Microsoft Windows VML Element Integer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017489" xml:lang="en">1017489</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2007-009.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2007-009.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MSKB</vuln:source>
      <vuln:reference href="http://support.microsoft.com/?kbid=929969" xml:lang="en">929969</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/122084" xml:lang="en">VU#122084</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457053/100/0/threaded" xml:lang="en">20070116 MS07-004 VML Integer Overflow Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457164/100/0/threaded" xml:lang="en">20070117 Re: MS07-004 VML Integer Overflow Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457274/100/0/threaded" xml:lang="en">HPSBST02184</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21930" xml:lang="en">21930</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-009A.html" xml:lang="en">TA07-009A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0105" xml:lang="en">ADV-2007-0105</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0129" xml:lang="en">ADV-2007-0129</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-004" xml:lang="en">MS07-004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31287" xml:lang="en">ie-vml-record-bo(31287)</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in the Vector Markup Language (VML) implementation (vgx.dll) in Microsoft Internet Explorer 5.01, 6, and 7 on Windows 2000 SP4, XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted web page that contains unspecified integer properties that cause insufficient memory allocation and trigger a buffer overflow, aka the "VML Buffer Overrun Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0025">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visual_studio_.net:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visual_studio_.net:2000:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visual_studio_.net:2003:gold"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:2000:sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:xp_sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:visual_studio_.net:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:visual_studio_.net:2000:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:visual_studio_.net:2003:gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:2000:sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:2003:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:xp_sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0025</vuln:cve-id>
    <vuln:published-datetime>2007-02-13T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:42:00.530-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A157" name="oval:org.mitre.oval:def:157"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/932041" xml:lang="en">VU#932041</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22476" xml:lang="en">22476</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017638" xml:lang="en">1017638</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" xml:lang="en">TA07-044A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0581" xml:lang="en">ADV-2007-0581</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-012" xml:lang="en">MS07-012</vuln:reference>
    </vuln:references>
    <vuln:summary>The MFC component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 and Visual Studio .NET 2000, 2002 SP1, 2003, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption. NOTE: this might be due to a stack-based buffer overflow in the AfxOleSetEditMenu function in MFC42u.dll.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0026">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:tablet_pc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:tablet_pc</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0026</vuln:cve-id>
    <vuln:published-datetime>2007-02-13T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:42:01.373-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A540" name="oval:org.mitre.oval:def:540"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/497756" xml:lang="en">VU#497756</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22483" xml:lang="en">22483</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017637" xml:lang="en">1017637</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" xml:lang="en">TA07-044A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0580" xml:lang="en">ADV-2007-0580</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-011" xml:lang="en">MS07-011</vuln:reference>
    </vuln:references>
    <vuln:summary>The OLE Dialog component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0027">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel_viewer:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2004"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2005"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2004::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:v.x::mac"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:excel:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel_viewer:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2004::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:v.x::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2004</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2005</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0027</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:30:34.523-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A119" name="oval:org.mitre.oval:def:119"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017487" xml:lang="en">1017487</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/749964" xml:lang="en">VU#749964</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457274/100/0/threaded" xml:lang="en">HPSBST02184</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21856" xml:lang="en">21856</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-009A.html" xml:lang="en">TA07-009A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0103" xml:lang="en">ADV-2007-0103</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-002" xml:lang="en">MS07-002</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via malformed IMDATA records that trigger memory corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0028">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel_viewer:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2004"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2005"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2004::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:v.x::mac"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:excel:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel_viewer:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2004::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:v.x::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2004</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2005</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0028</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:30:35.273-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A768" name="oval:org.mitre.oval:def:768"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017485" xml:lang="en">1017485</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-30.html" xml:lang="en">http://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-30.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.fortinet.com/FortiGuardCenter/advisory/FGA-2007-01.html" xml:lang="en">http://www.fortinet.com/FortiGuardCenter/advisory/FGA-2007-01.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/493185" xml:lang="en">VU#493185</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457274/100/0/threaded" xml:lang="en">HPSBST02184</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21952" xml:lang="en">21952</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-009A.html" xml:lang="en">TA07-009A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0103" xml:lang="en">ADV-2007-0103</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-002" xml:lang="en">MS07-002</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Excel 2000, 2002, 2003, Viewer 2003, Office 2004 for Mac, and Office v.X for Mac does not properly handle certain opcodes, which allows user-assisted remote attackers to execute arbitrary code via a crafted XLS file, which results in an "Improper Memory Access Vulnerability."  NOTE: an early disclosure of this issue used CVE-2006-3432, but only CVE-2007-0028 should be used.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0029">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel_viewer:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2004"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2005"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2004::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:v.x::mac"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:excel:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel_viewer:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2004::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:v.x::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2004</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2005</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0029</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:30:36.227-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1102" name="oval:org.mitre.oval:def:1102"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017487" xml:lang="en">1017487</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457274/100/0/threaded" xml:lang="en">HPSBST02184</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21877" xml:lang="en">21877</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-009A.html" xml:lang="en">TA07-009A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0103" xml:lang="en">ADV-2007-0103</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-002" xml:lang="en">MS07-002</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via a malformed string, aka "Excel Malformed String Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0030">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel_viewer:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2004"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2005"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2004::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:v.x::mac"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:excel:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel_viewer:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2004::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:v.x::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2004</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2005</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0030</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:30:36.883-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A323" name="oval:org.mitre.oval:def:323"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=460" xml:lang="en">20070109 Microsoft Excel Invalid Column Heap Corruption Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017487" xml:lang="en">1017487</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/302836" xml:lang="en">VU#302836</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457274/100/0/threaded" xml:lang="en">HPSBST02184</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21925" xml:lang="en">21925</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-009A.html" xml:lang="en">TA07-009A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0103" xml:lang="en">ADV-2007-0103</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-002" xml:lang="en">MS07-002</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via an Excel file with an out-of-range Column field in certain BIFF8 record types, which references arbitrary memory.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0031">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel_viewer:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2004"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2005"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2004::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:v.x::mac"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:excel:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel_viewer:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2004::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:v.x::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2004</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2005</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0031</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:30:37.710-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A753" name="oval:org.mitre.oval:def:753"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=461" xml:lang="en">20070109 Microsoft Excel Long Palette Heap Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017487" xml:lang="en">1017487</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/625532" xml:lang="en">VU#625532</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457274/100/0/threaded" xml:lang="en">HPSBST02184</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21922" xml:lang="en">21922</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-009A.html" xml:lang="en">TA07-009A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0103" xml:lang="en">ADV-2007-0103</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-002" xml:lang="en">MS07-002</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via a BIFF8 spreadsheet with a PALETTE record that contains a large number of entries.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0032">
    <vuln:cve-id>CVE-2007-0032</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:05.447-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:05.447-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2007. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0033">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2000"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2002"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2003"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook:2003</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0033</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:30:38.587-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A516" name="oval:org.mitre.oval:def:516"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017488" xml:lang="en">1017488</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/476900" xml:lang="en">VU#476900</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457274/100/0/threaded" xml:lang="en">HPSBST02184</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21931" xml:lang="en">21931</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-009A.html" xml:lang="en">TA07-009A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0104" xml:lang="en">ADV-2007-0104</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-003" xml:lang="en">MS07-003</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Outlook 2002 and 2003 allows user-assisted remote attackers to execute arbitrary code via a malformed VEVENT record in an .iCal meeting request or ICS file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0034">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2000"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2002"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2003"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook:2003</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0034</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:30:39.337-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A153" name="oval:org.mitre.oval:def:153"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017488" xml:lang="en">1017488</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.computerterrorism.com/research/ct09-01-2007.htm" xml:lang="en">http://www.computerterrorism.com/research/ct09-01-2007.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/271860" xml:lang="en">VU#271860</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456589/100/0/threaded" xml:lang="en">20070111 Computer Terrorism (UK) :: Incident Response Centre - Microsoft Outlook Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457274/100/0/threaded" xml:lang="en">HPSBST02184</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21936" xml:lang="en">21936</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-009A.html" xml:lang="en">TA07-009A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0104" xml:lang="en">ADV-2007-0104</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-003" xml:lang="en">MS07-003</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the Advanced Search (Finder.exe) feature of Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted Outlook Saved Searches (OSS) file that triggers memory corruption, aka "Microsoft Outlook Advanced Find Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0035">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2004::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2004"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2005"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2006"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2004::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2004</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2005</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2006</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0035</vuln:cve-id>
    <vuln:published-datetime>2007-05-08T18:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:20.590-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1737" name="oval:org.mitre.oval:def:1737"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/260777" xml:lang="en">VU#260777</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/468871/100/200/threaded" xml:lang="en">HPSBST02214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23804" xml:lang="en">23804</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018013" xml:lang="en">1018013</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" xml:lang="en">TA07-128A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1709" xml:lang="en">ADV-2007-1709</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-024" xml:lang="en">MS07-024</vuln:reference>
    </vuln:references>
    <vuln:summary>Word (or Word Viewer) in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, 2004 for Mac, and Works Suite 2004, 2005, and 2006 does not properly handle data in a certain array, which allows user-assisted remote attackers to execute arbitrary code, aka the "Word Array Overflow Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0036">
    <vuln:cve-id>CVE-2007-0036</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:05.463-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:05.480-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2007. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0037">
    <vuln:cve-id>CVE-2007-0037</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:05.497-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:05.497-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2007. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0038">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:gold::itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:gold::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1::itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp2::itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp2::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::gold:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional_x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:gold::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:gold::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp1::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp2::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp2::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::gold:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional_x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:professional_x64</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0038</vuln:cve-id>
    <vuln:published-datetime>2007-03-30T16:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:30:41.087-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1854" name="oval:org.mitre.oval:def:1854"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-03/0470.html" xml:lang="en">20070330 0-day ANI vulnerability in Microsoft Windows (CVE-2007-0038)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2542" xml:lang="en">2542</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.determina.com/security_center/security_advisories/securityadvisory_0day_032907.asp" xml:lang="en">http://www.determina.com/security_center/security_advisories/securityadvisory_0day_032907.asp</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/191609" xml:lang="en">VU#191609</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/464269/100/0/threaded" xml:lang="en">20070330 0-day ANI vulnerability in Microsoft Windows (CVE-2007-0038)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/464339/100/0/threaded" xml:lang="en">20070330 Re: 0-day ANI vulnerability in Microsoft Windows (CVE-2007-0038)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/464340/100/0/threaded" xml:lang="en">20070331 Re: 0-day ANI vulnerability in Microsoft Windows (CVE-2007-0038)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/464342/100/0/threaded" xml:lang="en">20070331 RE: [Full-disclosure] 0-day ANI vulnerability in Microsoft Windows(CVE-2007-0038)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/464459/100/100/threaded" xml:lang="en">20070402 More information on ZERT patch for ANI 0day</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/464460/100/100/threaded" xml:lang="en">20070402 MS announces out-of-band patch for ANI 0day</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/466186/100/200/threaded" xml:lang="en">HPSBST02206</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-089A.html" xml:lang="en">TA07-089A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-093A.html" xml:lang="en">TA07-093A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-100A.html" xml:lang="en">TA07-100A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1215" xml:lang="en">ADV-2007-1215</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-017" xml:lang="en">MS07-017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33301" xml:lang="en">win-ani-code-execution(33301)</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a large length value in the second (or later) anih block of a RIFF .ANI, cur, or .ico file, which results in memory corruption when processing cursors, animated cursors, and icons, a variant of CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this might be a duplicate of CVE-2007-1765; if so, then CVE-2007-0038 should be preferred.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0039">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2003:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2007"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:exchange_server:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:2003:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:2007</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0039</vuln:cve-id>
    <vuln:published-datetime>2007-05-08T19:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:30:43.257-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1593" name="oval:org.mitre.oval:def:1593"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-May/063232.html" xml:lang="en">20070509 Exchange Calendar MODPROPS Denial of Service (CVE-2007-0039)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.determina.com/security.research/vulnerabilities/exchange-ical-modprops.html" xml:lang="en">http://www.determina.com/security.research/vulnerabilities/exchange-ical-modprops.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/468047/100/0/threaded" xml:lang="en">20070508 Exchange Calendar MODPROPS Denial of Service (CVE-2007-0039)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/468871/100/200/threaded" xml:lang="en">HPSBST02214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23808" xml:lang="en">23808</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018015" xml:lang="en">1018015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" xml:lang="en">TA07-128A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1711" xml:lang="en">ADV-2007-1711</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-026" xml:lang="en">MS07-026</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33888" xml:lang="en">exchange-ical-dos(33888)</vuln:reference>
    </vuln:references>
    <vuln:summary>The Exchange Collaboration Data Objects (EXCDO) functionality in Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 allows remote attackers to cause a denial of service (crash) via an Internet Calendar (iCal) file containing multiple X-MICROSOFT-CDO-MODPROPS (MODPROPS) properties in which the second MODPROPS is longer than the first, which triggers a NULL pointer dereference and an unhandled exception.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0040">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp1:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:x64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp1:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2:x64</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0040</vuln:cve-id>
    <vuln:published-datetime>2007-07-10T18:30:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-04-30T10:27:13.913-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2012" name="oval:org.mitre.oval:def:2012"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html" xml:lang="en">SSRT071446</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://www.iss.net/threats/267.html" xml:lang="en">20070710 Microsoft Windows Active Directory Remote Code Execution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/487905" xml:lang="en">VU#487905</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/24800" xml:lang="en">24800</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018355" xml:lang="en">1018355</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-191A.html" xml:lang="en">TA07-191A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2481" xml:lang="en">ADV-2007-2481</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-039" xml:lang="en">MS07-039</vuln:reference>
    </vuln:references>
    <vuln:summary>The LDAP service in Windows Active Directory in Microsoft Windows 2000 Server SP4, Server 2003 SP1 and SP2, Server 2003 x64 Edition and SP2, and Server 2003 for Itanium-based Systems SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted LDAP request with an unspecified number of "convertible attributes."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0041">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:-"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:-"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:2.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:.net_framework:1.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:1.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0041</vuln:cve-id>
    <vuln:published-datetime>2007-07-10T18:30:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:38.340-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2093" name="oval:org.mitre.oval:def:2093"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html" xml:lang="en">SSRT071446</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/24778" xml:lang="en">24778</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018356" xml:lang="en">1018356</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-191A.html" xml:lang="en">TA07-191A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2482" xml:lang="en">ADV-2007-2482</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-040" xml:lang="en">MS07-040</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/34637" xml:lang="en">ms-dotnet-pe-loader-bo(34637)</vuln:reference>
    </vuln:references>
    <vuln:summary>The PE Loader service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer" and unvalidated message lengths, probably a buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0042">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:-"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:-"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:2.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:.net_framework:1.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:1.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0042</vuln:cve-id>
    <vuln:published-datetime>2007-07-10T18:30:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:38.340-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2070" name="oval:org.mitre.oval:def:2070"/>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html" xml:lang="en">SSRT071446</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://security-assessment.com/files/advisories/2007-07-11_Multiple_.NET_Null_Byte_Injection_Vulnerabilities.pdf" xml:lang="en">http://security-assessment.com/files/advisories/2007-07-11_Multiple_.NET_Null_Byte_Injection_Vulnerabilities.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018356" xml:lang="en">1018356</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-191A.html" xml:lang="en">TA07-191A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2482" xml:lang="en">ADV-2007-2482</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-040" xml:lang="en">MS07-040</vuln:reference>
    </vuln:references>
    <vuln:summary>Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to access configuration files and obtain sensitive information, and possibly bypass security mechanisms that try to constrain the final substring of a string, via %00 characters, related to use of %00 as a string terminator within POSIX functions but a data character within .NET strings, aka "Null Byte Termination Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0043">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000:-"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:-"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:1.1"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:.net_framework:2.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:.net_framework:1.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:1.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:.net_framework:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0043</vuln:cve-id>
    <vuln:published-datetime>2007-07-10T18:30:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:38.340-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1873" name="oval:org.mitre.oval:def:1873"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html" xml:lang="en">SSRT071446</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/24811" xml:lang="en">24811</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018356" xml:lang="en">1018356</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-191A.html" xml:lang="en">TA07-191A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2482" xml:lang="en">ADV-2007-2482</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-040" xml:lang="en">MS07-040</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/34639" xml:lang="en">ms-dotnet-jit-bo(34639)</vuln:reference>
    </vuln:references>
    <vuln:summary>The Just In Time (JIT) Compiler service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer," probably a buffer overflow, aka ".NET JIT Compiler Vulnerability".</vuln:summary>
  </entry>
  <entry id="CVE-2007-0044">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.1::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.1::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.2::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.2::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.3::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.3::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.4::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.4::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.5::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.5::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.6::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.6::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.7::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.7::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.8::elements"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.8::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.8::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_3d"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat:7.0::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.1::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.1::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.2::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.2::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.3::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.3::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.4::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.4::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.5::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.5::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.6::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.6::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.7::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.7::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.8::elements</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.8::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.8::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_3d</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0044</vuln:cve-id>
    <vuln:published-datetime>2007-01-03T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:30:44.477-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10042" name="oval:org.mitre.oval:def:10042"/>
    <vuln:cwe id="CWE-352"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf" xml:lang="en">http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html" xml:lang="en">SUSE-SA:2007:011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200701-16.xml" xml:lang="en">GLSA-200701-16</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2090" xml:lang="en">2090</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017469" xml:lang="en">1017469</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0144.html" xml:lang="en">RHSA-2008:0144</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455801/100/0/threaded" xml:lang="en">20070103 Adobe Acrobat Reader Plugin - Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21858" xml:lang="en">21858</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0032" xml:lang="en">ADV-2007-0032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.wisec.it/vulns.php?page=9" xml:lang="en">http://www.wisec.it/vulns.php?page=9</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31266" xml:lang="en">adobe-acrobat-pdf-csrf(31266)</vuln:reference>
    </vuln:references>
    <vuln:summary>Adobe Acrobat Reader Plugin before 8.0.0 for the Firefox, Internet Explorer, and Opera web browsers allows remote attackers to force the browser to make unauthorized requests to other web sites via a URL in the (1) FDF, (2) xml, and (3) xfdf AJAX request parameters, following the # (hash) character, aka "Universal CSRF and session riding."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0045">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.1::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.1::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.2::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.2::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.3::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.3::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.4::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.4::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.5::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.5::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.6::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.6::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.7::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.7::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.8::elements"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.8::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.8::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_3d"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat:7.0::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.1::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.1::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.2::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.2::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.3::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.3::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.4::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.4::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.5::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.5::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.6::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.6::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.7::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.7::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.8::elements</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.8::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.8::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_3d</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0045</vuln:cve-id>
    <vuln:published-datetime>2007-01-03T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:30:46.040-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6487" name="oval:org.mitre.oval:def:6487"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9693" name="oval:org.mitre.oval:def:9693"/>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://googlechromereleases.blogspot.com/2009/01/stable-beta-update-yahoo-mail-and.html" xml:lang="en">http://googlechromereleases.blogspot.com/2009/01/stable-beta-update-yahoo-mail-and.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" xml:lang="en">HPSBUX02153</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html" xml:lang="en">SUSE-SA:2007:011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200701-16.xml" xml:lang="en">GLSA-200701-16</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2090" xml:lang="en">2090</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017469" xml:lang="en">1017469</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1023007" xml:lang="en">1023007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131" xml:lang="en">SSA:2007-066-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102847-1" xml:lang="en">102847</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/advisories/apsa07-01.html" xml:lang="en">http://www.adobe.com/support/security/advisories/apsa07-01.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/advisories/apsa07-02.html" xml:lang="en">http://www.adobe.com/support/security/advisories/apsa07-02.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb07-01.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb07-01.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb09-15.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb09-15.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.disenchant.ch/blog/hacking-with-browser-plugins/34" xml:lang="en">http://www.disenchant.ch/blog/hacking-with-browser-plugins/34</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.gnucitizen.org/blog/danger-danger-danger/" xml:lang="en">http://www.gnucitizen.org/blog/danger-danger-danger/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.gnucitizen.org/blog/universal-pdf-xss-after-party" xml:lang="en">http://www.gnucitizen.org/blog/universal-pdf-xss-after-party</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/815960" xml:lang="en">VU#815960</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2007/mfsa2007-02.html" xml:lang="en">http://www.mozilla.org/security/announce/2007/mfsa2007-02.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0021.html" xml:lang="en">RHSA-2007:0021</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455790/100/0/threaded" xml:lang="en">20070103 Universal XSS with PDF files: highly dangerous</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455800/100/0/threaded" xml:lang="en">20070103 Re: Universal XSS with PDF files: highly dangerous</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455801/100/0/threaded" xml:lang="en">20070103 Adobe Acrobat Reader Plugin - Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455831/100/0/threaded" xml:lang="en">20070103 Re: [WEB SECURITY] Universal XSS with PDF files: highly dangerous</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455836/100/0/threaded" xml:lang="en">20070103 RE: [WEB SECURITY] Universal XSS with PDF files: highly dangerous</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455906/100/0/threaded" xml:lang="en">20070104 Universal PDF XSS After Party</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21858" xml:lang="en">21858</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-286B.html" xml:lang="en">TA09-286B</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0032" xml:lang="en">ADV-2007-0032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0957" xml:lang="en">ADV-2007-0957</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/2898" xml:lang="en">ADV-2009-2898</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.wisec.it/vulns.php?page=9" xml:lang="en">http://www.wisec.it/vulns.php?page=9</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31271" xml:lang="en">adobe-acrobat-pdf-xss(31271)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="https://rhn.redhat.com/errata/RHSA-2007-0017.html" xml:lang="en">RHSA-2007:0017</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2, for Mozilla Firefox, Microsoft Internet Explorer 6 SP1, Google Chrome, Opera 8.5.4 build 770, and Opera 9.10.8679 on Windows allow remote attackers to inject arbitrary JavaScript and conduct other attacks via a .pdf URL with a javascript: or res: URI with (1) FDF, (2) XML, and (3) XFDF AJAX parameters, or (4) an arbitrarily named name=URI anchor identifier, aka "Universal XSS (UXSS)."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0046">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0046</vuln:cve-id>
    <vuln:published-datetime>2007-01-03T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:30:51.367-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9684" name="oval:org.mitre.oval:def:9684"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf" xml:lang="en">http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html" xml:lang="en">SUSE-SA:2007:011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200701-16.xml" xml:lang="en">GLSA-200701-16</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2090" xml:lang="en">2090</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017469" xml:lang="en">1017469</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102847-1" xml:lang="en">102847</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb07-01.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb07-01.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0021.html" xml:lang="en">RHSA-2007:0021</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455801/100/0/threaded" xml:lang="en">20070103 Adobe Acrobat Reader Plugin - Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0032" xml:lang="en">ADV-2007-0032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0957" xml:lang="en">ADV-2007-0957</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.wisec.it/vulns.php?page=9" xml:lang="en">http://www.wisec.it/vulns.php?page=9</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31272" xml:lang="en">adobe-acrobat-msvcrt-code-execution(31272)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="https://rhn.redhat.com/errata/RHSA-2007-0017.html" xml:lang="en">RHSA-2007:0017</vuln:reference>
    </vuln:references>
    <vuln:summary>Double free vulnerability in the Adobe Acrobat Reader Plugin before 8.0.0, as used in Mozilla Firefox 1.5.0.7, allows remote attackers to execute arbitrary code by causing an error via a javascript: URI call to document.write in the (1) FDF, (2) XML, or (3) XFDF AJAX request parameters.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0047">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0047</vuln:cve-id>
    <vuln:published-datetime>2007-01-03T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:55.360-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf" xml:lang="en">http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html" xml:lang="en">SUSE-SA:2007:011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017469" xml:lang="en">1017469</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0032" xml:lang="en">ADV-2007-0032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31291" xml:lang="en">adobe-acrobat-xmlhttp-response-splitting(31291)</vuln:reference>
    </vuln:references>
    <vuln:summary>CRLF injection vulnerability in Adobe Acrobat Reader Plugin before 8.0.0, when used with the Microsoft.XMLHTTP ActiveX object in Internet Explorer, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the javascript: URI in the (1) FDF, (2) XML, or (3) XFDF AJAX request parameters.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0048">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.1::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.1::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.2::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.2::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.3::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.3::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.4::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.4::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.5::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.5::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.6::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.6::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.7::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.7::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.8::elements"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.8::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat:7.0.8::standard"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_3d"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat:7.0::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.1::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.1::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.2::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.2::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.3::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.3::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.4::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.4::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.5::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.5::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.6::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.6::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.7::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.7::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.8::elements</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.8::professional</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat:7.0.8::standard</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_3d</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0048</vuln:cve-id>
    <vuln:published-datetime>2007-01-03T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:30:52.883-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6348" name="oval:org.mitre.oval:def:6348"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf" xml:lang="en">http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://googlechromereleases.blogspot.com/2009/01/stable-beta-update-yahoo-mail-and.html" xml:lang="en">http://googlechromereleases.blogspot.com/2009/01/stable-beta-update-yahoo-mail-and.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html" xml:lang="en">SUSE-SA:2007:011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200701-16.xml" xml:lang="en">GLSA-200701-16</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2090" xml:lang="en">2090</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017469" xml:lang="en">1017469</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1023007" xml:lang="en">1023007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb07-01.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb07-01.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb09-15.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb09-15.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455801/100/0/threaded" xml:lang="en">20070103 Adobe Acrobat Reader Plugin - Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA09-286B.html" xml:lang="en">TA09-286B</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0032" xml:lang="en">ADV-2007-0032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/2898" xml:lang="en">ADV-2009-2898</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.wisec.it/vulns.php?page=9" xml:lang="en">http://www.wisec.it/vulns.php?page=9</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31273" xml:lang="en">adobe-acrobat-character-dos(31273)</vuln:reference>
    </vuln:references>
    <vuln:summary>Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2, when used with Internet Explorer, Google Chrome, or Opera, allows remote attackers to cause a denial of service (memory consumption) via a long sequence of # (hash) characters appended to a PDF URL, related to a "cross-site scripting issue."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0049">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:geckovich:tasktracker:1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:geckovich:tasktracker_pro:1.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:geckovich:tasktracker:1.4</vuln:product>
      <vuln:product>cpe:/a:geckovich:tasktracker_pro:1.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0049</vuln:cve-id>
    <vuln:published-datetime>2007-01-04T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:55.627-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21847" xml:lang="en">21847</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31235" xml:lang="en">tasktrackerpro-customize-auth-bypass(31235)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3068" xml:lang="en">3068</vuln:reference>
    </vuln:references>
    <vuln:summary>Geckovich TaskTracker Pro 1.5 and earlier allows remote attackers to add administrative or other accounts via an Add action with a modified GroupID in a direct request to Customize.asp.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0050">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:openpinboard:openpinboard:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openpinboard:openpinboard:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0050</vuln:cve-id>
    <vuln:published-datetime>2007-01-04T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:30:54.523-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2007-01/0176.html" xml:lang="en">20070106 Re: OpenPinboard &lt;= Remote File Include</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455795/100/0/threaded" xml:lang="en">20070103 OpenPinboard &lt;= Remote File Include</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455818/100/0/threaded" xml:lang="en">20070103 Re: OpenPinboard &lt;= Remote File Include</vuln:reference>
    </vuln:references>
    <vuln:summary>** DISPUTED **  PHP remote file inclusion vulnerability in index.php in OpenPinboard 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the language parameter.  NOTE: this issue has been disputed by the developer and a third party, since the variable is set before use. CVE analysis suggests that there is a small time window of risk before the installation is complete.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0051">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:iphoto:6.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:iphoto:6.0.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0051</vuln:cve-id>
    <vuln:published-datetime>2007-01-04T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:30:54.820-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-134"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0100.html" xml:lang="en">20070104 DMA[2007-0104a] - 'iLife iPhoto Photocasing Format String Vulnerability'</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305215" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305215</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2007/Mar//msg00003.html" xml:lang="en">APPLE-SA-2007-03-13</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-04-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-04-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455968/100/0/threaded" xml:lang="en">20070104 DMA[2007-0104a] - 'iLife iPhoto Photocasing Format String Vulnerability'</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21871" xml:lang="en">21871</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0057" xml:lang="en">ADV-2007-0057</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31281" xml:lang="en">iphoto-xmltitle-format-string(31281)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3080" xml:lang="en">3080</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in Apple iPhoto 6.0.5 (316), and other versions before 6.0.6, allows remote user-assisted attackers to execute arbitrary code via a crafted photocast with format string specifiers in the title of an RSS iPhoto feed.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0052">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:vizayn_haber:vizayn_haber"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vizayn_haber:vizayn_haber</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0052</vuln:cve-id>
    <vuln:published-datetime>2007-01-04T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:55.737-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21836" xml:lang="en">21836</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0015" xml:lang="en">ADV-2007-0015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31213" xml:lang="en">vicayn-haberdetay-sql-injection(31213)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3061" xml:lang="en">3061</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in haberdetay.asp in Vizayn Haber allows remote attackers to execute arbitrary SQL commands via the id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0053">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:asp_siteware:autodealer:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:asp_siteware:autodealer:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0053</vuln:cve-id>
    <vuln:published-datetime>2007-01-04T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:55.783-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21833" xml:lang="en">21833</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0016" xml:lang="en">ADV-2007-0016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31219" xml:lang="en">autodealer-detail-sql-injection(31219)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3062" xml:lang="en">3062</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in detail.asp in ASP SiteWare autoDealer 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the iPro parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0054">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:belchior_foundry:vcard_pro"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:belchior_foundry:vcard_pro</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0054</vuln:cve-id>
    <vuln:published-datetime>2007-01-04T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:30:55.790-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455615/100/0/threaded" xml:lang="en">20070101 vBulletin vCard PRO XSS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21844" xml:lang="en">21844</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31182" xml:lang="en">vcard-gbrowse-xss(31182)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in gbrowse.php in Belchior Foundry vCard PRO allows remote attackers to inject arbitrary web script or HTML via the sortby parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0055">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:fersch:formbankserver:1.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:fersch:formbankserver:1.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0055</vuln:cve-id>
    <vuln:published-datetime>2007-01-04T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:55.847-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0012" xml:lang="en">ADV-2007-0012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31214" xml:lang="en">formbankserver-name-directory-traversal(31214)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3063" xml:lang="en">3063</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in formbankcgi.exe/AbfrageForm in Formbankserver 1.9 allows remote attackers to read arbitrary files via directory traversal sequences in the Name parameter.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0056">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ashopsoftware:ashop_administration_panel"/>
        <cpe-lang:fact-ref name="cpe:/a:ashopsoftware:ashop_deluxe:4.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ashopsoftware:ashop_administration_panel</vuln:product>
      <vuln:product>cpe:/a:ashopsoftware:ashop_deluxe:4.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0056</vuln:cve-id>
    <vuln:published-datetime>2007-01-04T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:30:56.117-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2091" xml:lang="en">2091</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455629/100/0/threaded" xml:lang="en">20070101 AShop Shopping Cart Multiple XSS Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21845" xml:lang="en">21845</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0028" xml:lang="en">ADV-2007-0028</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31178" xml:lang="en">ashop-multiple-scripts-xss(31178)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in AShop Deluxe 4.5 and AShop Administration Panel allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to (a) ashop/catalogue.php and (b) ashop/basket.php, the (2) exp parameter to ashop/catalogue.php, the (3) searchstring parameter to (c) ashop/search.php, the (4) checkout and (5) action parameters to (d) ashop/shipping.php, the cat parameter to (f) cart-path/admin/editcatalogue.php, and the (7) resultpage parameter to (g) cart-path/admin/salesadmin.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0057">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cisco:network_admission_control_manager_and_server_system_software:3.6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:network_admission_control_manager_and_server_system_software:3.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:network_admission_control_manager_and_server_system_software:3.6.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:network_admission_control_manager_and_server_system_software:3.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:network_admission_control_manager_and_server_system_software:3.6.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:network_admission_control_manager_and_server_system_software:3.6.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:network_admission_control_manager_and_server_system_software:3.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:network_admission_control_manager_and_server_system_software:3.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:network_admission_control_manager_and_server_system_software:3.6.4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:network_admission_control_manager_and_server_system_software:3.6.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:network_admission_control_manager_and_server_system_software:3.6.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:network_admission_control_manager_and_server_system_software:4.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:network_admission_control_manager_and_server_system_software:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:network_admission_control_manager_and_server_system_software:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:network_admission_control_manager_and_server_system_software:4.0.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:network_admission_control_manager_and_server_system_software:4.0.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:network_admission_control_manager_and_server_system_software:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:network_admission_control_manager_and_server_system_software:4.0.3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cisco:network_admission_control_manager_and_server_system_software:3.6.0.1</vuln:product>
      <vuln:product>cpe:/a:cisco:network_admission_control_manager_and_server_system_software:3.6.1</vuln:product>
      <vuln:product>cpe:/a:cisco:network_admission_control_manager_and_server_system_software:3.6.1.1</vuln:product>
      <vuln:product>cpe:/a:cisco:network_admission_control_manager_and_server_system_software:3.6.2</vuln:product>
      <vuln:product>cpe:/a:cisco:network_admission_control_manager_and_server_system_software:3.6.2.1</vuln:product>
      <vuln:product>cpe:/a:cisco:network_admission_control_manager_and_server_system_software:3.6.2.2</vuln:product>
      <vuln:product>cpe:/a:cisco:network_admission_control_manager_and_server_system_software:3.6.3</vuln:product>
      <vuln:product>cpe:/a:cisco:network_admission_control_manager_and_server_system_software:3.6.4</vuln:product>
      <vuln:product>cpe:/a:cisco:network_admission_control_manager_and_server_system_software:3.6.4.0.1</vuln:product>
      <vuln:product>cpe:/a:cisco:network_admission_control_manager_and_server_system_software:3.6.4.1</vuln:product>
      <vuln:product>cpe:/a:cisco:network_admission_control_manager_and_server_system_software:3.6.4.2</vuln:product>
      <vuln:product>cpe:/a:cisco:network_admission_control_manager_and_server_system_software:4.0.0.1</vuln:product>
      <vuln:product>cpe:/a:cisco:network_admission_control_manager_and_server_system_software:4.0.1</vuln:product>
      <vuln:product>cpe:/a:cisco:network_admission_control_manager_and_server_system_software:4.0.2</vuln:product>
      <vuln:product>cpe:/a:cisco:network_admission_control_manager_and_server_system_software:4.0.2.1</vuln:product>
      <vuln:product>cpe:/a:cisco:network_admission_control_manager_and_server_system_software:4.0.2.2</vuln:product>
      <vuln:product>cpe:/a:cisco:network_admission_control_manager_and_server_system_software:4.0.3</vuln:product>
      <vuln:product>cpe:/a:cisco:network_admission_control_manager_and_server_system_software:4.0.3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0057</vuln:cve-id>
    <vuln:published-datetime>2007-01-04T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-11-01T12:53:19.347-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2018-10-22T11:51:05.483-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-255"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017465" xml:lang="en">1017465</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20070103-CleanAccess.shtml" xml:lang="en">20070103 Multiple Vulnerabilities in Cisco Clean Access</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0030" xml:lang="en">ADV-2007-0030</vuln:reference>
    </vuln:references>
    <vuln:summary>Cisco Clean Access (CCA) 3.6.x through 3.6.4.2 and 4.0.x through 4.0.3.2 does not properly configure or allow modification of a shared secret authentication key, which causes all devices to have the same shared sercet and allows remote attackers to gain unauthorized access.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0058">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cisco:network_admission_control_manager_and_server_system_software:3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:network_admission_control_manager_and_server_system_software:3.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:network_admission_control_manager_and_server_system_software:3.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:network_admission_control_manager_and_server_system_software:3.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:network_admission_control_manager_and_server_system_software:3.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:network_admission_control_manager_and_server_system_software:3.5.9"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:network_admission_control_manager_and_server_system_software:3.6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:network_admission_control_manager_and_server_system_software:3.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:network_admission_control_manager_and_server_system_software:3.6.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cisco:network_admission_control_manager_and_server_system_software:3.5.1</vuln:product>
      <vuln:product>cpe:/a:cisco:network_admission_control_manager_and_server_system_software:3.5.2</vuln:product>
      <vuln:product>cpe:/a:cisco:network_admission_control_manager_and_server_system_software:3.5.3</vuln:product>
      <vuln:product>cpe:/a:cisco:network_admission_control_manager_and_server_system_software:3.5.4</vuln:product>
      <vuln:product>cpe:/a:cisco:network_admission_control_manager_and_server_system_software:3.5.5</vuln:product>
      <vuln:product>cpe:/a:cisco:network_admission_control_manager_and_server_system_software:3.5.9</vuln:product>
      <vuln:product>cpe:/a:cisco:network_admission_control_manager_and_server_system_software:3.6.0.1</vuln:product>
      <vuln:product>cpe:/a:cisco:network_admission_control_manager_and_server_system_software:3.6.1</vuln:product>
      <vuln:product>cpe:/a:cisco:network_admission_control_manager_and_server_system_software:3.6.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0058</vuln:cve-id>
    <vuln:published-datetime>2007-01-04T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:04.370-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2018-10-18T09:35:34.963-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017465" xml:lang="en">1017465</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20070103-CleanAccess.shtml" xml:lang="en">20070103 Multiple Vulnerabilities in Cisco Clean Access</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0030" xml:lang="en">ADV-2007-0030</vuln:reference>
    </vuln:references>
    <vuln:summary>Cisco Clean Access (CCA) 3.5.x through 3.5.9 and 3.6.x through 3.6.1.1 on the Clean Access Manager (CAM) allows remote attackers to bypass authentication and download arbitrary manual database backups by guessing the snapshot filename using brute force, then making a direct request for the file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0059">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:quicktime:3.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0059</vuln:cve-id>
    <vuln:published-datetime>2007-01-04T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:17.370-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305149" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305149</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html" xml:lang="en">APPLE-SA-2007-03-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-03-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-03-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.gnucitizen.org/blog/backdooring-quicktime-movies/" xml:lang="en">http://www.gnucitizen.org/blog/backdooring-quicktime-movies/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/304064" xml:lang="en">VU#304064</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-zone scripting vulnerability in Apple Quicktime 3 to 7.1.3 allows remote user-assisted attackers to execute arbitrary code and list filesystem contents via a QuickTime movie (.MOV) with an HREF Track (HREFTrack) that contains an automatic action tag with a local URI, which is executed in a local zone during preview, as exploited by a MySpace worm.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0060">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ca:advantage_data_transport:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:brightstor_portal:11.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:brightstor_san_manager:11.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:brightstor_san_manager:11.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:cleverpath_aion:10.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:cleverpath_ecm:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:cleverpath_olap:5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:cleverpath_predictive_analysis_server:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:cleverpath_predictive_analysis_server:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:etrust_admin:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:etrust_admin:2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:etrust_admin:2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:etrust_admin:2.9"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:etrust_admin:8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:etrust_admin:8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_application_performance_monitor:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_application_performance_monitor:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_asset_management:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_asset_management:3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_asset_management:3.2:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_asset_management:3.2:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_asset_management:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_asset_management:4.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_data_transport_option:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_enterprise_job_manager:1.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_enterprise_job_manager:1.0:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_jasmine:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_management:4.0::lotus_notes_domino"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_management:4.0::microsoft_exchange"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_management:4.1::microsoft_exchange"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_management:5.0::web_servers"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_management:5.0.1::web_servers"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_network_and_systems_management:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_network_and_systems_management:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_nsm_wireless_network_management_option:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_remote_control:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_remote_control:6.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_service_level_management:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_service_level_management:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_service_level_management:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_service_level_management:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_software_delivery:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_software_delivery:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_software_delivery:3.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_software_delivery:3.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_software_delivery:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_software_delivery:4.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_tng:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_tng:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_tng:2.2:::ja"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_tng:2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:unicenter_tng:2.4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ca:advantage_data_transport:3.0</vuln:product>
      <vuln:product>cpe:/a:ca:brightstor_portal:11.1</vuln:product>
      <vuln:product>cpe:/a:ca:brightstor_san_manager:11.1</vuln:product>
      <vuln:product>cpe:/a:ca:brightstor_san_manager:11.5</vuln:product>
      <vuln:product>cpe:/a:ca:cleverpath_aion:10.0</vuln:product>
      <vuln:product>cpe:/a:ca:cleverpath_ecm:3.5</vuln:product>
      <vuln:product>cpe:/a:ca:cleverpath_olap:5.1</vuln:product>
      <vuln:product>cpe:/a:ca:cleverpath_predictive_analysis_server:2.0</vuln:product>
      <vuln:product>cpe:/a:ca:cleverpath_predictive_analysis_server:3.0</vuln:product>
      <vuln:product>cpe:/a:ca:etrust_admin:2.1</vuln:product>
      <vuln:product>cpe:/a:ca:etrust_admin:2.4</vuln:product>
      <vuln:product>cpe:/a:ca:etrust_admin:2.7</vuln:product>
      <vuln:product>cpe:/a:ca:etrust_admin:2.9</vuln:product>
      <vuln:product>cpe:/a:ca:etrust_admin:8.0</vuln:product>
      <vuln:product>cpe:/a:ca:etrust_admin:8.1</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_application_performance_monitor:3.0</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_application_performance_monitor:3.5</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_asset_management:3.1</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_asset_management:3.2</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_asset_management:3.2:sp1</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_asset_management:3.2:sp2</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_asset_management:4.0</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_asset_management:4.0:sp1</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_data_transport_option:2.0</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_enterprise_job_manager:1.0:sp1</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_enterprise_job_manager:1.0:sp2</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_jasmine:3.0</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_management:4.0::lotus_notes_domino</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_management:4.0::microsoft_exchange</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_management:4.1::microsoft_exchange</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_management:5.0::web_servers</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_management:5.0.1::web_servers</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_network_and_systems_management:3.0</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_network_and_systems_management:3.1</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_nsm_wireless_network_management_option:3.0</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_remote_control:6.0</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_remote_control:6.0:sp1</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_service_level_management:3.0</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_service_level_management:3.0.1</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_service_level_management:3.0.2</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_service_level_management:3.5</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_software_delivery:3.0</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_software_delivery:3.1</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_software_delivery:3.1:sp1</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_software_delivery:3.1:sp2</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_software_delivery:4.0</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_software_delivery:4.0:sp1</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_tng:2.1</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_tng:2.2</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_tng:2.2:::ja</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_tng:2.4</vuln:product>
      <vuln:product>cpe:/a:ca:unicenter_tng:2.4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0060</vuln:cve-id>
    <vuln:published-datetime>2007-07-25T20:30:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:30:57.010-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://supportconnectw.ca.com/public/dto_transportit/infodocs/camsgquevul-secnot.asp" xml:lang="en">http://supportconnectw.ca.com/public/dto_transportit/infodocs/camsgquevul-secnot.asp</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.ca.com/us/securityadvisor/newsinfo/collateral.aspx?cid=149809" xml:lang="en">http://www.ca.com/us/securityadvisor/newsinfo/collateral.aspx?cid=149809</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://www.iss.net/threats/272.html" xml:lang="en">20070724 CA Message Queuing Server (Cam.exe) Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/474602/100/0/threaded" xml:lang="en">20070725 [CAID 35527]: CA Message Queuing (CAM / CAFT) Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/25051" xml:lang="en">25051</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018449" xml:lang="en">1018449</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2638" xml:lang="en">ADV-2007-2638</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32234" xml:lang="en">systems-management-bo(32234)</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in the Message Queuing Server (Cam.exe) in CA (formerly Computer Associates) Message Queuing (CAM / CAFT) software before 1.11 Build 54_4 on Windows and NetWare, as used in CA Advantage Data Transport, eTrust Admin, certain BrightStor products, certain CleverPath products, and certain Unicenter products, allows remote attackers to execute arbitrary code via a crafted message to TCP port 3104.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0061">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:vmware:ace:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:ace:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:ace:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:ace:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:player:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:player:1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:player:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:player:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:player:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:player:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:player:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:server:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:server:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:server:1.0.1_build_29996"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:server:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:server:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.0_build_13124"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.1_build_19175"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.3_build_34685"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.3_build_42958"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.4_build_44386"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:vmware:esx:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:vmware:esx:2.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:vmware:esx:2.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:vmware:esx:2.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:vmware:esx:3.0.0"/>
        <cpe-lang:fact-ref name="cpe:/o:vmware:esx:3.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:6.06::~~lts~~~"/>
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:6.10"/>
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:7.04"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vmware:ace:1.0</vuln:product>
      <vuln:product>cpe:/a:vmware:ace:1.0.1</vuln:product>
      <vuln:product>cpe:/a:vmware:ace:1.0.2</vuln:product>
      <vuln:product>cpe:/a:vmware:ace:2.0</vuln:product>
      <vuln:product>cpe:/a:vmware:player:1.0</vuln:product>
      <vuln:product>cpe:/a:vmware:player:1.0.0</vuln:product>
      <vuln:product>cpe:/a:vmware:player:1.0.1</vuln:product>
      <vuln:product>cpe:/a:vmware:player:1.0.2</vuln:product>
      <vuln:product>cpe:/a:vmware:player:1.0.3</vuln:product>
      <vuln:product>cpe:/a:vmware:player:1.0.4</vuln:product>
      <vuln:product>cpe:/a:vmware:player:2.0</vuln:product>
      <vuln:product>cpe:/a:vmware:server:1.0</vuln:product>
      <vuln:product>cpe:/a:vmware:server:1.0.1</vuln:product>
      <vuln:product>cpe:/a:vmware:server:1.0.1_build_29996</vuln:product>
      <vuln:product>cpe:/a:vmware:server:1.0.2</vuln:product>
      <vuln:product>cpe:/a:vmware:server:1.0.3</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5.0_build_13124</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5.1</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5.1_build_19175</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5.2</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5.3</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5.3_build_34685</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5.3_build_42958</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5.4</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5.4_build_44386</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:6.0</vuln:product>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:6.06::~~lts~~~</vuln:product>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:6.10</vuln:product>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:7.04</vuln:product>
      <vuln:product>cpe:/o:vmware:esx:2.0.2</vuln:product>
      <vuln:product>cpe:/o:vmware:esx:2.1.3</vuln:product>
      <vuln:product>cpe:/o:vmware:esx:2.5.3</vuln:product>
      <vuln:product>cpe:/o:vmware:esx:2.5.4</vuln:product>
      <vuln:product>cpe:/o:vmware:esx:3.0.0</vuln:product>
      <vuln:product>cpe:/o:vmware:esx:3.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0061</vuln:cve-id>
    <vuln:published-datetime>2007-09-21T15:17:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-07-16T08:20:24.747-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2019-07-02T08:56:22.300-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html" xml:lang="en">20070920 VMSA-2007-0006 Critical security updates for all supported versions of VMware ESX Server, VMware Server, VMware Workstation, VMware ACE, and VMware Player</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200711-23.xml" xml:lang="en">GLSA-200711-23</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://www.iss.net/threats/275.html" xml:lang="en">20070919 VMWare DHCP Server Remote Code Execution Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/25729" xml:lang="en">25729</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018717" xml:lang="en">1018717</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-543-1" xml:lang="en">USN-543-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/ace/doc/releasenotes_ace.html" xml:lang="en">http://www.vmware.com/support/ace/doc/releasenotes_ace.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html" xml:lang="en">http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/player/doc/releasenotes_player.html" xml:lang="en">http://www.vmware.com/support/player/doc/releasenotes_player.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/player2/doc/releasenotes_player2.html" xml:lang="en">http://www.vmware.com/support/player2/doc/releasenotes_player2.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/server/doc/releasenotes_server.html" xml:lang="en">http://www.vmware.com/support/server/doc/releasenotes_server.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html" xml:lang="en">http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html" xml:lang="en">http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/3229" xml:lang="en">ADV-2007-3229</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33101" xml:lang="en">dhcp-malformed-packet-bo(33101)</vuln:reference>
    </vuln:references>
    <vuln:summary>The DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows remote attackers to execute arbitrary code via a malformed packet that triggers "corrupt stack memory."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0062">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:vmware:ace:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:ace:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:player:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:player:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:server:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:vmware_workstation:6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:4.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.0_build_13124"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.1_build_19175"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.3_build_34685"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.3_build_42958"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.4_build_44386"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vmware:ace:1.0.3</vuln:product>
      <vuln:product>cpe:/a:vmware:ace:2.0</vuln:product>
      <vuln:product>cpe:/a:vmware:player:1.0.4</vuln:product>
      <vuln:product>cpe:/a:vmware:player:2.0</vuln:product>
      <vuln:product>cpe:/a:vmware:server:1.0.3</vuln:product>
      <vuln:product>cpe:/a:vmware:vmware_workstation:6.0.1</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:3.4</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:4.0</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:4.0.1</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:4.0.2</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:4.5.2</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5.0_build_13124</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5.1</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5.1_build_19175</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5.3_build_34685</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5.3_build_42958</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5.4</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5.4_build_44386</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0062</vuln:cve-id>
    <vuln:published-datetime>2007-09-21T15:17:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:30:57.820-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.gentoo.org/show_bug.cgi?id=227135" xml:lang="en">http://bugs.gentoo.org/show_bug.cgi?id=227135</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html" xml:lang="en">20070920 VMSA-2007-0006 Critical security updates for all supported versions of VMware ESX Server, VMware Server, VMware Workstation, VMware ACE, and VMware Player</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00000.html" xml:lang="en">SUSE-SR:2009:005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200711-23.xml" xml:lang="en">GLSA-200711-23</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200808-05.xml" xml:lang="en">GLSA-200808-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://wiki.rpath.com/Advisories:rPSA-2009-0041" xml:lang="en">http://wiki.rpath.com/Advisories:rPSA-2009-0041</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://www.iss.net/threats/275.html" xml:lang="en">20070919 VMWare DHCP Server Remote Code Execution Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2009:153" xml:lang="en">MDVSA-2009:153</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/501759/100/0/threaded" xml:lang="en">20090312 rPSA-2009-0041-1 dhclient dhcp libdhcp4client</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/25729" xml:lang="en">25729</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018717" xml:lang="en">1018717</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-543-1" xml:lang="en">USN-543-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/ace/doc/releasenotes_ace.html" xml:lang="en">http://www.vmware.com/support/ace/doc/releasenotes_ace.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html" xml:lang="en">http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/player/doc/releasenotes_player.html" xml:lang="en">http://www.vmware.com/support/player/doc/releasenotes_player.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/player2/doc/releasenotes_player2.html" xml:lang="en">http://www.vmware.com/support/player2/doc/releasenotes_player2.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/server/doc/releasenotes_server.html" xml:lang="en">http://www.vmware.com/support/server/doc/releasenotes_server.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html" xml:lang="en">http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html" xml:lang="en">http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/3229" xml:lang="en">ADV-2007-3229</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=339561" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=339561</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33102" xml:lang="en">dhcp-param-overflow(33102)</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in the ISC dhcpd 3.0.x before 3.0.7 and 3.1.x before 3.1.1; and the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528; allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a malformed DHCP packet with a large dhcp-max-message-size that triggers a stack-based buffer overflow, related to servers configured to send many DHCP options to clients.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0063">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:vmware:ace:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:ace:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:ace:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:ace:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:player:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:player:1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:player:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:player:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:player:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:player:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:player:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:server:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:server:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:server:1.0.1_build_29996"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:server:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:server:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.0_build_13124"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.1_build_19175"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.3_build_34685"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.3_build_42958"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.4_build_44386"/>
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:vmware:esx:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:vmware:esx:2.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:vmware:esx:2.5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:vmware:esx:2.5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:vmware:esx:3.0.0"/>
        <cpe-lang:fact-ref name="cpe:/o:vmware:esx:3.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:6.06::~~lts~~~"/>
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:6.10"/>
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:7.04"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vmware:ace:1.0</vuln:product>
      <vuln:product>cpe:/a:vmware:ace:1.0.1</vuln:product>
      <vuln:product>cpe:/a:vmware:ace:1.0.2</vuln:product>
      <vuln:product>cpe:/a:vmware:ace:2.0</vuln:product>
      <vuln:product>cpe:/a:vmware:player:1.0</vuln:product>
      <vuln:product>cpe:/a:vmware:player:1.0.0</vuln:product>
      <vuln:product>cpe:/a:vmware:player:1.0.1</vuln:product>
      <vuln:product>cpe:/a:vmware:player:1.0.2</vuln:product>
      <vuln:product>cpe:/a:vmware:player:1.0.3</vuln:product>
      <vuln:product>cpe:/a:vmware:player:1.0.4</vuln:product>
      <vuln:product>cpe:/a:vmware:player:2.0</vuln:product>
      <vuln:product>cpe:/a:vmware:server:1.0</vuln:product>
      <vuln:product>cpe:/a:vmware:server:1.0.1</vuln:product>
      <vuln:product>cpe:/a:vmware:server:1.0.1_build_29996</vuln:product>
      <vuln:product>cpe:/a:vmware:server:1.0.2</vuln:product>
      <vuln:product>cpe:/a:vmware:server:1.0.3</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5.0_build_13124</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5.1</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5.1_build_19175</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5.2</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5.3</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5.3_build_34685</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5.3_build_42958</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5.4</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:5.5.4_build_44386</vuln:product>
      <vuln:product>cpe:/a:vmware:workstation:6.0</vuln:product>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:6.06::~~lts~~~</vuln:product>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:6.10</vuln:product>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:7.04</vuln:product>
      <vuln:product>cpe:/o:vmware:esx:2.0.2</vuln:product>
      <vuln:product>cpe:/o:vmware:esx:2.1.3</vuln:product>
      <vuln:product>cpe:/o:vmware:esx:2.5.3</vuln:product>
      <vuln:product>cpe:/o:vmware:esx:2.5.4</vuln:product>
      <vuln:product>cpe:/o:vmware:esx:3.0.0</vuln:product>
      <vuln:product>cpe:/o:vmware:esx:3.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0063</vuln:cve-id>
    <vuln:published-datetime>2007-09-21T15:17:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-07-16T08:20:32.293-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2019-07-02T08:57:10.770-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-191"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html" xml:lang="en">20070920 VMSA-2007-0006 Critical security updates for all supported versions of VMware ESX Server, VMware Server, VMware Workstation, VMware ACE, and VMware Player</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200711-23.xml" xml:lang="en">GLSA-200711-23</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://www.iss.net/threats/275.html" xml:lang="en">20070919 VMWare DHCP Server Remote Code Execution Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/25729" xml:lang="en">25729</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018717" xml:lang="en">1018717</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-543-1" xml:lang="en">USN-543-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/ace/doc/releasenotes_ace.html" xml:lang="en">http://www.vmware.com/support/ace/doc/releasenotes_ace.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html" xml:lang="en">http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/player/doc/releasenotes_player.html" xml:lang="en">http://www.vmware.com/support/player/doc/releasenotes_player.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/player2/doc/releasenotes_player2.html" xml:lang="en">http://www.vmware.com/support/player2/doc/releasenotes_player2.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/server/doc/releasenotes_server.html" xml:lang="en">http://www.vmware.com/support/server/doc/releasenotes_server.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html" xml:lang="en">http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html" xml:lang="en">http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/3229" xml:lang="en">ADV-2007-3229</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33103" xml:lang="en">dhcp-param-underflow(33103)</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows remote attackers to execute arbitrary code via a malformed DHCP packet that triggers a stack-based buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0064">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_media_format_runtime:7.1"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_media_format_runtime:9"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:x64"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_media_format_runtime:9.5"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:x64"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_media_format_runtime:9.5::x64"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:-"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:x64"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_media_format_runtime:11"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:x64"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_media_services:9.1"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:windows_media_format_runtime:7.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:windows_media_format_runtime:9</vuln:product>
      <vuln:product>cpe:/a:microsoft:windows_media_format_runtime:9.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:windows_media_format_runtime:9.5::x64</vuln:product>
      <vuln:product>cpe:/a:microsoft:windows_media_format_runtime:11</vuln:product>
      <vuln:product>cpe:/a:microsoft:windows_media_services:9.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0064</vuln:cve-id>
    <vuln:published-datetime>2007-12-11T19:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:38.340-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3622" name="oval:org.mitre.oval:def:3622"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/319385" xml:lang="en">VU#319385</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/485268/100/0/threaded" xml:lang="en">SSRT071506</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/26776" xml:lang="en">26776</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019074" xml:lang="en">1019074</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-345A.html" xml:lang="en">TA07-345A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/4183" xml:lang="en">ADV-2007-4183</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-068" xml:lang="en">MS07-068</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in Windows Media Format Runtime 7.1, 9, 9.5, 9.5 x64 Edition, 11, and Windows Media Services 9.1 for Microsoft Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via a crafted Advanced Systems Format (ASF) file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0065">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:office:::mac%2bos"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:visual_basic:6.0:sp6"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office:::mac%2bos</vuln:product>
      <vuln:product>cpe:/a:microsoft:visual_basic:6.0:sp6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0065</vuln:cve-id>
    <vuln:published-datetime>2008-02-12T18:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:42:23.983-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5388" name="oval:org.mitre.oval:def:5388"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" xml:lang="en">HPSBST02314</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27661" xml:lang="en">27661</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019373" xml:lang="en">1019373</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-043C.html" xml:lang="en">TA08-043C</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0510/references" xml:lang="en">ADV-2008-0510</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-008" xml:lang="en">MS08-008</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in Object Linking and Embedding (OLE) Automation in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, Office 2004 for Mac, and Visual basic 6.0 SP6 allows remote attackers to execute arbitrary code via a crafted script request.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0066">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:home_server"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:small_business_server:2003::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::gold:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:standard"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_server_2003::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp1:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:-:sp2:x64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:home_server</vuln:product>
      <vuln:product>cpe:/a:microsoft:small_business_server:2003::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::gold:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server::sp2:standard</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_server_2003::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:-:sp1:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:-:sp2:x64</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0066</vuln:cve-id>
    <vuln:published-datetime>2008-01-08T15:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-02-26T09:04:00.853-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5271" name="oval:org.mitre.oval:def:5271"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://blogs.technet.com/swi/archive/2008/01/08/ms08-001-part-2-the-case-of-the-moderate-icmp-mitigations.aspx" xml:lang="en">http://blogs.technet.com/swi/archive/2008/01/08/ms08-001-part-2-the-case-of-the-moderate-icmp-mitigations.aspx</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1019166" xml:lang="en">1019166</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://www.iss.net/threats/282.html" xml:lang="en">20070108 Multiple (3) Microsoft Windows TCP/IP Remote Code Execution and DoS Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/486317/100/0/threaded" xml:lang="en">SSRT080003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27139" xml:lang="en">27139</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-008A.html" xml:lang="en">TA08-008A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0069" xml:lang="en">ADV-2008-0069</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-001" xml:lang="en">MS08-001</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/39254" xml:lang="en">win-tcpip-icmp-dos(39254)</vuln:reference>
    </vuln:references>
    <vuln:summary>The kernel in Microsoft Windows 2000 SP4, XP SP2, and Server 2003, when ICMP Router Discovery Protocol (RDP) is enabled, allows remote attackers to cause a denial of service via fragmented router advertisement ICMP packets that trigger an out-of-bounds read, aka "Windows Kernel TCP/IP/ICMP Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0067">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.0.2_cf2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.5.4::fp1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.5.4::fp2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.5.5::fp1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:6.5.5::fp2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:7.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:7.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_web_server:7.0.2::fp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.0</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.0.1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.0.2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.0.2_cf2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.0.3</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.0.4</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.0.5</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.5.0</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.5.1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.5.2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.5.3</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.5.4</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.5.4::fp1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.5.4::fp2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.5.5</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.5.5::fp1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:6.5.5::fp2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:7.0</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:7.0.1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:7.0.2</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino_web_server:7.0.2::fp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0067</vuln:cve-id>
    <vuln:published-datetime>2007-06-06T06:30:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:56.890-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/24307" xml:lang="en">24307</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018189" xml:lang="en">1018189</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2046" xml:lang="en">ADV-2007-2046</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?uid=swg21257251" xml:lang="en">http://www-1.ibm.com/support/docview.wss?uid=swg21257251</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/34689" xml:lang="en">domino-unspecified-dos(34689)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the Lotus Domino Web Server 6.0, 6.5.x before 6.5.6, and 7.0.x before 7.0.3 allows remote attackers to cause a denial of service (daemon crash) via requests for URLs that reference certain files.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0068">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:7.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:7.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:lotus_domino:7.0</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:7.0.1</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:7.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0068</vuln:cve-id>
    <vuln:published-datetime>2007-06-06T17:30:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:57.127-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/24322" xml:lang="en">24322</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2063" xml:lang="en">ADV-2007-2063</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?uid=swg21258784" xml:lang="en">http://www-1.ibm.com/support/docview.wss?uid=swg21258784</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/34718" xml:lang="en">domino-signature-privilege-escalation(34718)</vuln:reference>
    </vuln:references>
    <vuln:summary>IBM Lotus Domino 7.0.x before 7.0.3 does not revalidate the signature on a signed scheduled agent after the agent is modified, which allows remote authenticated users to gain privileges via a modified agent in a server database.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0069">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2003_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0069</vuln:cve-id>
    <vuln:published-datetime>2008-01-08T15:46:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:01.963-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5370" name="oval:org.mitre.oval:def:5370"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://blogs.technet.com/swi/archive/2008/01/08/ms08-001-part-3-the-case-of-the-igmp-network-critical.aspx" xml:lang="en">http://blogs.technet.com/swi/archive/2008/01/08/ms08-001-part-3-the-case-of-the-igmp-network-critical.aspx</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1019166" xml:lang="en">1019166</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://www.iss.net/threats/282.html" xml:lang="en">20070108 Multiple (3) Microsoft Windows TCP/IP Remote Code Execution and DoS Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/115083" xml:lang="en">VU#115083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/486317/100/0/threaded" xml:lang="en">SSRT080003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27100" xml:lang="en">27100</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-008A.html" xml:lang="en">TA08-008A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0069" xml:lang="en">ADV-2008-0069</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-001" xml:lang="en">MS08-001</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/39452" xml:lang="en">win-ssm-igmp-bo(39452)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/39453" xml:lang="en">win-ssm-mld-bo(39453)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the kernel in Microsoft Windows XP SP2, Server 2003, and Vista allows remote attackers to cause a denial of service (CPU consumption) and possibly execute arbitrary code via crafted (1) IGMPv3 and (2) MLDv2 packets that trigger memory corruption, aka "Windows Kernel TCP/IP/IGMPv3 and MLDv2 Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0071">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:8.0.22.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:8.0.24.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:8.0.33.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:8.0.34.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:8.0.35.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:8.0.39.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.16.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.18d60"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.20"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.20.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.28"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.28.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.31"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.31.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.45.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.47.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.48.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.112.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.114.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:flash_player:9.0.115.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:flash_player:8.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:8.0.22.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:8.0.24.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:8.0.33.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:8.0.34.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:8.0.35.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:8.0.39.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.8.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.9.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.16</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.16.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.18d60</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.20</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.20.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.28</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.28.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.31</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.31.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.45.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.47.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.48.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.112.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.114.0</vuln:product>
      <vuln:product>cpe:/a:adobe:flash_player:9.0.115.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0071</vuln:cve-id>
    <vuln:published-datetime>2008-04-09T17:05:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:24.687-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2018-10-17T13:18:26.483-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10379" name="oval:org.mitre.oval:def:10379"/>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://blogs.adobe.com/psirt/2008/05/potential_flash_player_issue.html" xml:lang="en">http://blogs.adobe.com/psirt/2008/05/potential_flash_player_issue.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://documents.iss.net/whitepapers/IBM_X-Force_WP_final.pdf" xml:lang="en">http://documents.iss.net/whitepapers/IBM_X-Force_WP_final.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://isc.sans.org/diary.html?storyid=4465" xml:lang="en">http://isc.sans.org/diary.html?storyid=4465</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008//May/msg00001.html" xml:lang="en">APPLE-SA-2008-05-28</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00006.html" xml:lang="en">SUSE-SA:2008:022</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-238305-1" xml:lang="en">238305</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb08-11.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb08-11.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200804-21.xml" xml:lang="en">GLSA-200804-21</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://www.iss.net/threats/289.html" xml:lang="en">20080408 Adobe Flash Player Invalid Pointer Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/159523" xml:lang="en">VU#159523</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/395473" xml:lang="en">VU#395473</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.matasano.com/log/1032/this-new-vulnerability-dowds-inhuman-flash-exploit/" xml:lang="en">http://www.matasano.com/log/1032/this-new-vulnerability-dowds-inhuman-flash-exploit/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0221.html" xml:lang="en">RHSA-2008:0221</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28695" xml:lang="en">28695</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/29386" xml:lang="en">29386</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019811" xml:lang="en">1019811</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-100A.html" xml:lang="en">TA08-100A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-149A.html" xml:lang="en">TA08-149A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-150A.html" xml:lang="en">TA08-150A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/1662/references" xml:lang="en">ADV-2008-1662</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/1697" xml:lang="en">ADV-2008-1697</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/1724/references" xml:lang="en">ADV-2008-1724</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-08-032/" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-08-032/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/37277" xml:lang="en">multimedia-file-integer-overflow(37277)</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via a crafted SWF file with a negative Scene Count value, which passes a signed comparison, is used as an offset of a NULL pointer, and triggers a buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0072">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:serverprotect:5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:serverprotect:5.58"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:trend_micro:serverprotect:5.7</vuln:product>
      <vuln:product>cpe:/a:trend_micro:serverprotect:5.58</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0072</vuln:cve-id>
    <vuln:published-datetime>2008-11-17T18:30:00.313-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:57.280-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://blogs.iss.net/archive/trend.html" xml:lang="en">http://blogs.iss.net/archive/trend.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://www.iss.net/threats/309.html" xml:lang="en">20081111 Trend Micro ServerProtect [PROCEDURE NAME REDACTED] Heap Overflows (3)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/768681" xml:lang="en">VU#768681</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/32261" xml:lang="en">32261</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/3127" xml:lang="en">ADV-2008-3127</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/38760" xml:lang="en">application-rpc-read-bo(38760)</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to a read operation over RPC.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0073">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:serverprotect:5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:serverprotect:5.58"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:trend_micro:serverprotect:5.7</vuln:product>
      <vuln:product>cpe:/a:trend_micro:serverprotect:5.58</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0073</vuln:cve-id>
    <vuln:published-datetime>2008-11-17T18:30:00.343-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:57.327-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://blogs.iss.net/archive/trend.html" xml:lang="en">http://blogs.iss.net/archive/trend.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://www.iss.net/threats/309.html" xml:lang="en">20081111 Trend Micro ServerProtect [PROCEDURE NAME REDACTED] Heap Overflows (3)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/768681" xml:lang="en">VU#768681</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/32261" xml:lang="en">32261</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/3127" xml:lang="en">ADV-2008-3127</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/39050" xml:lang="en">application-rpc-file-read-bo(39050)</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to a file read operation over RPC.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0074">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:serverprotect:5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:serverprotect:5.58"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:trend_micro:serverprotect:5.7</vuln:product>
      <vuln:product>cpe:/a:trend_micro:serverprotect:5.58</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0074</vuln:cve-id>
    <vuln:published-datetime>2008-11-17T18:30:00.360-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:57.563-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://blogs.iss.net/archive/trend.html" xml:lang="en">http://blogs.iss.net/archive/trend.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://www.iss.net/threats/309.html" xml:lang="en">20081111 Trend Micro ServerProtect [PROCEDURE NAME REDACTED] Heap Overflows (3)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/768681" xml:lang="en">VU#768681</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/32261" xml:lang="en">32261</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/3127" xml:lang="en">ADV-2008-3127</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/39051" xml:lang="en">application-rpc-folder-read-bo(39051)</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to a folder read operation over RPC.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0075">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:aspbb:aspbb"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:aspbb:aspbb</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0075</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:03.040-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2100" xml:lang="en">2100</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.aria-security.com/forum/showthread.php?t=82" xml:lang="en">http://www.aria-security.com/forum/showthread.php?t=82</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455683/100/0/threaded" xml:lang="en">20070102 AspBB Remote Password Disclosure</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31230" xml:lang="en">aspbb-aspbb-info-disclosure(31230)</vuln:reference>
    </vuln:references>
    <vuln:summary>AspBB stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user passwords via a direct request for db/aspbb.mdb.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0076">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:2enetworx:openforum"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:2enetworx:openforum</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0076</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:03.400-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2099" xml:lang="en">2099</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.aria-security.com/forum/showthread.php?t=80" xml:lang="en">http://www.aria-security.com/forum/showthread.php?t=80</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455684/100/0/threaded" xml:lang="en">20070102 Openforum Remote password Disclosure</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31209" xml:lang="en">openforum-openforum-password-disclosure(31209)</vuln:reference>
    </vuln:references>
    <vuln:summary>Openforum stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user passwords via a direct request for openforum.mdb.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0077">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:lblog:lblog"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:lblog:lblog</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0077</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:03.777-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2098" xml:lang="en">2098</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017462" xml:lang="en">1017462</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.aria-security.com/forum/showthread.php?t=79" xml:lang="en">http://www.aria-security.com/forum/showthread.php?t=79</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455681/100/0/threaded" xml:lang="en">20070102 lblog Remote Password Disclosure</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31229" xml:lang="en">lblog-newfolder-information-disclosure(31229)</vuln:reference>
    </vuln:references>
    <vuln:summary>lblog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for a certain file in admin/db/newFolder/.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0078">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:battleblog:battleblog:1.0d"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:battleblog:battleblog:1.0d</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0078</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:04.197-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2097" xml:lang="en">2097</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.aria-security.com/forum/showthread.php?t=76" xml:lang="en">http://www.aria-security.com/forum/showthread.php?t=76</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455614/100/0/threaded" xml:lang="en">20070101 BattleBlog Database Download Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31224" xml:lang="en">battleblog-blankmaster-info-disclosure(31224)</vuln:reference>
    </vuln:references>
    <vuln:summary>BattleBlog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for database/blankmaster.mdb.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0079">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:rblog:rblog"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rblog:rblog</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0079</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:04.527-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2102" xml:lang="en">2102</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.aria-security.com/forum/showthread.php?t=77" xml:lang="en">http://www.aria-security.com/forum/showthread.php?t=77</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455626/100/0/threaded" xml:lang="en">20070101 rblog Database Download Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31200" xml:lang="en">rblog-database-info-disclosure(31200)</vuln:reference>
    </vuln:references>
    <vuln:summary>rblog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) data/admin.mdb or (2) data/rblog.mdb.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0080">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:freeradius:freeradius:1.1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:freeradius:freeradius:1.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0080</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:04.947-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017463" xml:lang="en">1017463</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-February/001304.html" xml:lang="en">20070211 FreeRADIUS dispute of CVE-2007-0080</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.freeradius.org/security.html" xml:lang="en">http://www.freeradius.org/security.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455678/100/0/threaded" xml:lang="en">20070102 FreeRadius 1.1.3 SMB_Handle_Type SMB_Connect_Server arbitrary code execution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455812/100/0/threaded" xml:lang="en">20070103 Re: FreeRadius 1.1.3 SMB_Handle_Type SMB_Connect_Server arbitrary code execution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31248" xml:lang="en">freeradius-smbconnectserver-bo(31248)</vuln:reference>
    </vuln:references>
    <vuln:summary>** DISPUTED **  Buffer overflow in the SMB_Connect_Server function in FreeRadius 1.1.3 and earlier allows attackers to execute arbitrary code related to the server desthost field of an SMB_Handle_Type instance.  NOTE: the impact of this issue has been disputed by a reliable third party and the vendor, who states that exploitation is limited "only to local administrators who have write access to the server configuration files."  CVE concurs with the dispute.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0081">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sunbelt:sunbelt_kerio_personal_firewall:4.3.246"/>
        <cpe-lang:fact-ref name="cpe:/a:sunbelt:sunbelt_kerio_personal_firewall:4.3.268"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sunbelt:sunbelt_kerio_personal_firewall:4.3.246</vuln:product>
      <vuln:product>cpe:/a:sunbelt:sunbelt_kerio_personal_firewall:4.3.268</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0081</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:05.417-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2095" xml:lang="en">2095</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.matousec.com/info/advisories/Kerio-Fake-iphlpapi-DLL-injection.php" xml:lang="en">http://www.matousec.com/info/advisories/Kerio-Fake-iphlpapi-DLL-injection.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455624/100/0/threaded" xml:lang="en">20070101 Kerio Fake 'iphlpapi' DLL injection Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21828" xml:lang="en">21828</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31232" xml:lang="en">kerio-directory-code-execution(31232)</vuln:reference>
    </vuln:references>
    <vuln:summary>Sunbelt Kerio Personal Firewall (SKPF) 4.3.268 and 4.3.246, and possibly other versions allows local users to provide a Trojan horse iphlpapi.dll to SKPF by placing it in the installation directory.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0082">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:imgallery:imgallery:2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:imgallery:imgallery:2.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:imgallery:imgallery:2.4</vuln:product>
      <vuln:product>cpe:/a:imgallery:imgallery:2.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0082</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:55.910-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21827" xml:lang="en">21827</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0010" xml:lang="en">ADV-2007-0010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31237" xml:lang="en">imgallery-start1-file-upload(31237)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3049" xml:lang="en">3049</vuln:reference>
    </vuln:references>
    <vuln:summary>users_adm/start1.php in IMGallery 2.5 and earlier does not properly handle files with multiple extensions, which allows remote authenticated users to upload and execute arbitrary PHP scripts.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0083">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nuked-klan:nuked-klan:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:nuked-klan:nuked-klan:1.2_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:nuked-klan:nuked-klan:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:nuked-klan:nuked-klan:1.3_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:nuked-klan:nuked-klan:1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:nuked-klan:nuked-klan:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:nuked-klan:nuked-klan:1.5_sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:nuked-klan:nuked-klan:1.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nuked-klan:nuked-klan:1.2</vuln:product>
      <vuln:product>cpe:/a:nuked-klan:nuked-klan:1.2_beta</vuln:product>
      <vuln:product>cpe:/a:nuked-klan:nuked-klan:1.3</vuln:product>
      <vuln:product>cpe:/a:nuked-klan:nuked-klan:1.3_beta</vuln:product>
      <vuln:product>cpe:/a:nuked-klan:nuked-klan:1.4</vuln:product>
      <vuln:product>cpe:/a:nuked-klan:nuked-klan:1.5</vuln:product>
      <vuln:product>cpe:/a:nuked-klan:nuked-klan:1.5_sp2</vuln:product>
      <vuln:product>cpe:/a:nuked-klan:nuked-klan:1.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0083</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:05.867-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2101" xml:lang="en">2101</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455726/100/0/threaded" xml:lang="en">20070102 Nuked Klan &lt;= 1.7 Remote Cookie Disclosure Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21850" xml:lang="en">21850</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Nuked Klan 1.7 and earlier allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in a getURL statement in a .swf file, as demonstrated by "Remote Cookie Disclosure."  NOTE: it could be argued that this is an issue in Shockwave instead of Nuked Klan.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0084">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:message_compiler:1.00.5239"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:message_compiler:1.00.5239</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0084</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:06.133-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455729/100/0/threaded" xml:lang="en">20070102 Windows NT Message Compiler 1.00.5239 arbitrary code execution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455789/100/0/threaded" xml:lang="en">20070103 Re: Windows NT Message Compiler 1.00.5239 arbitrary code execution</vuln:reference>
    </vuln:references>
    <vuln:summary>** DISPUTED **  Buffer overflow in the Windows NT Message Compiler (MC) 1.00.5239 on Microsoft Windows XP allows local users to gain privileges via a long MC-filename.  NOTE: this issue has been disputed by a reliable third party who states that the compiler is not a privileged program, so privilege boundaries cannot be crossed.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0085">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:openbsd:openbsd:3.9</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0085</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:58.077-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.0</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://ilja.netric.org/files/Unusual%20bugs%2023c3.pdf" xml:lang="en">http://ilja.netric.org/files/Unusual%20bugs%2023c3.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://marc.info/?l=openbsd-cvs&amp;m=116781980706409&amp;w=2" xml:lang="en">[openbsd-cvs] 20070103 Re: CVS: cvs.openbsd.org: src</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://marc.info/?l=openbsd-cvs&amp;m=116785923301416&amp;w=2" xml:lang="en">[openbsd-cvs] 20070103 CVS: cvs.openbsd.org: www</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017468" xml:lang="en">1017468</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>OPENBSD</vuln:source>
      <vuln:reference href="http://www.openbsd.org/errata.html#agp" xml:lang="en">[4.0] 007: SECURITY FIX: January 3, 2007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>OPENBSD</vuln:source>
      <vuln:reference href="http://www.openbsd.org/errata39.html#agp" xml:lang="en">[3.9] 017: SECURITY FIX: January 3, 2007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0043" xml:lang="en">ADV-2007-0043</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31276" xml:lang="en">openbsd-vga-privilege-escalation(31276)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in sys/dev/pci/vga_pci.c in the VGA graphics driver for wscons in OpenBSD 3.9 and 4.0, when the kernel is compiled with the PCIAGP option and a non-AGP device is being used, allows local users to gain privileges via unspecified vectors, possibly related to agp_ioctl NULL pointer reference.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0086">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:http_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0086</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:06.337-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455833/100/0/threaded" xml:lang="en">20070103 a cheesy Apache / IIS DoS vuln (+a question)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455879/100/0/threaded" xml:lang="en">20070104 Re: a cheesy Apache / IIS DoS vuln (+a question)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455882/100/0/threaded" xml:lang="en">20070104 Re: a cheesy Apache / IIS DoS vuln (+a question)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455920/100/0/threaded" xml:lang="en">20070104 Re: a cheesy Apache / IIS DoS vuln (+a question)</vuln:reference>
    </vuln:references>
    <vuln:summary>** DISPUTED **  The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment.  NOTE: the severity of this issue has been disputed by third parties, who state that the large window size required by the attack is not normally supported or configured by the server, or that a DDoS-style attack would accomplish the same goal.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0087">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_information_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0087</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:06.650-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455833/100/0/threaded" xml:lang="en">20070103 a cheesy Apache / IIS DoS vuln (+a question)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455879/100/0/threaded" xml:lang="en">20070104 Re: a cheesy Apache / IIS DoS vuln (+a question)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455882/100/0/threaded" xml:lang="en">20070104 Re: a cheesy Apache / IIS DoS vuln (+a question)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455920/100/0/threaded" xml:lang="en">20070104 Re: a cheesy Apache / IIS DoS vuln (+a question)</vuln:reference>
    </vuln:references>
    <vuln:summary>** DISPUTED **  Microsoft Internet Information Services (IIS), when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment.  NOTE: the severity of this issue has been disputed by third parties, who state that the large window size required by the attack is not normally supported or configured by the server, or that a DDoS-style attack would accomplish the same goal.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0088">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:openmedia:openmedia"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openmedia:openmedia</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0088</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:06.947-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2103" xml:lang="en">2103</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455786/100/0/threaded" xml:lang="en">20070102 openmedia local read file</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31258" xml:lang="en">openmedia-page-directory-traversal(31258)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple directory traversal vulnerabilities in openmedia allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) src parameter to page.php or the (2) format parameter to search_form.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0089">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:jgbbs:jgbbs:3.0:beta_1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:jgbbs:jgbbs:3.0:beta_1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0089</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:07.307-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://aria-security.com/forum/showthread.php?t=87" xml:lang="en">http://aria-security.com/forum/showthread.php?t=87</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455832/100/0/threaded" xml:lang="en">20070103 jgbbs</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31274" xml:lang="en">jgbbs-bbs-information-disclosure(31274)</vuln:reference>
    </vuln:references>
    <vuln:summary>jgbbs stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db/bbs.mdb.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0090">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:fermentigrafici:wineglass"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:fermentigrafici:wineglass</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0090</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:07.680-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://aria-security.com/forum/showthread.php?p=112" xml:lang="en">http://aria-security.com/forum/showthread.php?p=112</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455807/100/0/threaded" xml:lang="en">20070103 WineGlass "data.mdb" Remote Password Disclosure</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0037" xml:lang="en">ADV-2007-0037</vuln:reference>
    </vuln:references>
    <vuln:summary>WineGlass stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db/data.mdb.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0091">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:katy_whitton_web_development:newscmslite"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:katy_whitton_web_development:newscmslite</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0091</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:55.973-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31222" xml:lang="en">newscmslite-newscms-info-disclosure(31222)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3066" xml:lang="en">3066</vuln:reference>
    </vuln:references>
    <vuln:summary>newsCMSlite stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for newsCMS.mdb.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0092">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:e-smart_cart:e-smart_cart:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:e-smart_cart:e-smart_cart:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0092</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:56.020-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0036" xml:lang="en">ADV-2007-0036</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31243" xml:lang="en">esmartcart-productdetail-sql-injection(31243)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3074" xml:lang="en">3074</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in productdetail.asp in E-SMARTCART 1.0 allows remote attackers to execute arbitrary SQL commands via the product_id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0093">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cms-center:simple_web_cms"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cms-center:simple_web_cms</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0093</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:07.993-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://acid-root.new.fr/poc/18070102.txt" xml:lang="en">http://acid-root.new.fr/poc/18070102.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2106" xml:lang="en">2106</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455814/100/0/threaded" xml:lang="en">20070103 Simple Web Content Management System SQL Injection Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0040" xml:lang="en">ADV-2007-0040</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31261" xml:lang="en">swcms-page-sql-injection(31261)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3076" xml:lang="en">3076</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in page.php in Simple Web Content Management System allows remote attackers to execute arbitrary SQL commands via the id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0094">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sven_moderow:sven_moderow_guestbook:0.3a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sven_moderow:sven_moderow_guestbook:0.3a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0094</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:08.510-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://aria-security.com/forum/showthread.php?p=114" xml:lang="en">http://aria-security.com/forum/showthread.php?p=114</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2105" xml:lang="en">2105</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455788/100/0/threaded" xml:lang="en">20070103 GuestBook v0.3a Remote Password Disclosure</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31245" xml:lang="en">guestbook-gbook-information-disclosure(31245)</vuln:reference>
    </vuln:references>
    <vuln:summary>Sven Moderow GuestBook 0.3a stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for (1) gbook97.mdb or (2) gbook.mdb in ~db/.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0095">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.9.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.9.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0095</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:58.420-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0034.html" xml:lang="en">20070102 Inforamtion Discloser Vulnerabilities in "phpMyAdmin"</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051544.html" xml:lang="en">20070102 Inforamtion Discloser Vulnerabilities in  phpMyAdmin</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2104" xml:lang="en">2104</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:199" xml:lang="en">MDKSA-2007:199</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31223" xml:lang="en">phpmyadmin-darkblueorange-path-disclosure(31223)</vuln:reference>
    </vuln:references>
    <vuln:summary>phpMyAdmin 2.9.1.1 allows remote attackers to obtain sensitive information via a direct request for themes/darkblue_orange/layout.inc.php, which reveals the path in an error message.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0096">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:carbon_communities:carbon_communities:2.4d"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:carbon_communities:carbon_communities:2.4d</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0096</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:58.483-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://aria-security.com/forum/showthread.php?t=85" xml:lang="en">http://aria-security.com/forum/showthread.php?t=85</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0038" xml:lang="en">ADV-2007-0038</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31253" xml:lang="en">carboncommunities-carbon2-info-disclosure(31253)</vuln:reference>
    </vuln:references>
    <vuln:summary>CarbonCommunities stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for DataBase/Carbon2.4d.mdb.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0097">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:conexware:powerarchiver_2006:9.64.02"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:conexware:powerarchiver_2006:9.64.02</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0097</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:08.823-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://marc.info/?l=full-disclosure&amp;m=116791509125050&amp;w=2" xml:lang="en">20070104 [vuln.sg] PowerArchiver PAISO.DLL Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://vuln.sg/powarc964-en.html" xml:lang="en">http://vuln.sg/powarc964-en.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455892/100/0/threaded" xml:lang="en">20070104 [vuln.sg] PowerArchiver PAISO.DLL Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0041" xml:lang="en">ADV-2007-0041</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31263" xml:lang="en">powerarchiver-loadtree-readheader-bo(31263)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple stack-based buffer overflows in the (1) LoadTree and (2) ReadHeader functions in PAISO.DLL 1.7.3.0 (1.7.3 beta) in ConeXware PowerArchiver 2006 9.64.02 allow user-assisted attackers to execute arbitrary code via a crafted ISO file containing a file within several nested directories.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0098">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:verliadmin:verliadmin:0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:verliadmin:verliadmin:0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0098</vuln:cve-id>
    <vuln:published-datetime>2007-01-05T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:56.127-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0035" xml:lang="en">ADV-2007-0035</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31241" xml:lang="en">verliadmin-language-file-include(31241)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3075" xml:lang="en">3075</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in language.php in VerliAdmin 0.3 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by language.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0099">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:xml_core_services:3.0"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_explorer:6"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_explorer:6</vuln:product>
      <vuln:product>cpe:/a:microsoft:xml_core_services:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0099</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:09.353-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5793" name="oval:org.mitre.oval:def:5793"/>
    <vuln:cwe id="CWE-362"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0113.html" xml:lang="en">20070104 Re: Concurrency strikes MSIE (potentially exploitablemsxml3 flaws)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://isc.sans.org/diary.php?storyid=2004" xml:lang="en">http://isc.sans.org/diary.php?storyid=2004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=122703006921213&amp;w=2" xml:lang="en">SSRT080164</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://seclists.org/fulldisclosure/2007/Jan/0110.html" xml:lang="en">20070104 Concurrency strikes MSIE (potentially exploitable msxml3 flaws)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1021164" xml:lang="en">1021164</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455965/100/0/threaded" xml:lang="en">20070104 Concurrency strikes MSIE (potentially exploitable msxml3 flaws)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455986/100/0/threaded" xml:lang="en">20070104 RE: [Full-disclosure] Concurrency strikes MSIE (potentially exploitablemsxml3 flaws)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456343/100/0/threaded" xml:lang="en">20070104 Re: RE: [Full-disclosure] Concurrency strikes MSIE (potentially exploitablemsxml3 flaws)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21872" xml:lang="en">21872</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-316A.html" xml:lang="en">TA08-316A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/3111" xml:lang="en">ADV-2008-3111</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-069" xml:lang="en">MS08-069</vuln:reference>
    </vuln:references>
    <vuln:summary>Race condition in the msxml3 module in Microsoft XML Core Services 3.0, as used in Internet Explorer 6 and other applications, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via many nested tags in an XML document in an IFRAME, when synchronous document rendering is frequently disrupted with asynchronous events, as demonstrated using a JavaScript timer, which can trigger NULL pointer dereferences or memory corruption, aka "MSXML Memory Corruption Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0100">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:perforce:perforce_client"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:perforce:perforce_client</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0100</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:10.650-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455977/100/0/threaded" xml:lang="en">20070104 Perforce client: security hole by design</vuln:reference>
    </vuln:references>
    <vuln:summary>The Perforce client does not restrict the set of files that it overwrites upon receiving a request from the server, which allows remote attackers to overwrite arbitrary files by modifying the client config file on the server, or by operating a malicious server.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0101">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:spine:spine:1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:spine:spine:1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0101</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:58.627-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://spine.sourceforge.net/changelog.html" xml:lang="en">http://spine.sourceforge.net/changelog.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0042" xml:lang="en">ADV-2007-0042</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31283" xml:lang="en">spine-unspecified-csrf(31283)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site request forgery (CSRF) vulnerability in SPINE allows remote attackers to perform unauthorized actions as administrators via unspecified vectors.  NOTE: some of these details are obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0102">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:preview:3.0.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:preview:3.0.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0102</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:58.687-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305214" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-06-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-06-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21910" xml:lang="en">21910</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017749" xml:lang="en">1017749</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" xml:lang="en">TA07-072A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0930" xml:lang="en">ADV-2007-0930</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31364" xml:lang="en">multiple-vendor-pdf-code-execution(31364)</vuln:reference>
    </vuln:references>
    <vuln:summary>The Adobe PDF specification 1.3, as implemented by Apple Mac OS X Preview, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0103">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0103</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:58.733-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305214" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-06-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-06-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21910" xml:lang="en">21910</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017749" xml:lang="en">1017749</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" xml:lang="en">TA07-072A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0930" xml:lang="en">ADV-2007-0930</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31364" xml:lang="en">multiple-vendor-pdf-code-execution(31364)</vuln:reference>
    </vuln:references>
    <vuln:summary>The Adobe PDF specification 1.3, as implemented by Adobe Acrobat before 8.0.0, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0104">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:3.0.1_pl1"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:3.0.1_pl2"/>
        <cpe-lang:fact-ref name="cpe:/a:xpdf:xpdf:3.0_pl2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.4"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:kde:kde:3.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xpdf:xpdf:3.0</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:3.0.1</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:3.0.1_pl1</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:3.0.1_pl2</vuln:product>
      <vuln:product>cpe:/a:xpdf:xpdf:3.0_pl2</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.2</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.2.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.2.2</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.2.3</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.3</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.3.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.3.2</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.4</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.4.1</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.4.2</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.4.3</vuln:product>
      <vuln:product>cpe:/o:kde:kde:3.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0104</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:10.853-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305214" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-06-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-06-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017514" xml:lang="en">1017514</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.novell.com/techcenter/psdb/44d7cb9b669d58e0ce5aa5d7ab2c7c53.html" xml:lang="en">http://support.novell.com/techcenter/psdb/44d7cb9b669d58e0ce5aa5d7ab2c7c53.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kde.org/info/security/advisory-20070115-1.txt" xml:lang="en">http://www.kde.org/info/security/advisory-20070115-1.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:018" xml:lang="en">MDKSA-2007:018</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:019" xml:lang="en">MDKSA-2007:019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:020" xml:lang="en">MDKSA-2007:020</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:021" xml:lang="en">MDKSA-2007:021</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:022" xml:lang="en">MDKSA-2007:022</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:024" xml:lang="en">MDKSA-2007:024</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_3_sr.html" xml:lang="en">SUSE-SR:2007:003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457055/100/0/threaded" xml:lang="en">20070116 [KDE Security Advisory] kpdf/kword/xpdf denial of service vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21910" xml:lang="en">21910</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017749" xml:lang="en">1017749</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-410-1" xml:lang="en">USN-410-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-410-2" xml:lang="en">USN-410-2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" xml:lang="en">TA07-072A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0203" xml:lang="en">ADV-2007-0203</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0212" xml:lang="en">ADV-2007-0212</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0244" xml:lang="en">ADV-2007-0244</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0930" xml:lang="en">ADV-2007-0930</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31364" xml:lang="en">multiple-vendor-pdf-code-execution(31364)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-964" xml:lang="en">https://issues.rpath.com/browse/RPL-964</vuln:reference>
    </vuln:references>
    <vuln:summary>The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and other products, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0105">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cisco:secure_access_control_server:4.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cisco:secure_access_control_server:4.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0105</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:58.877-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017475" xml:lang="en">1017475</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20070105-csacs.shtml" xml:lang="en">20070105 Multiple Vulnerabilities in Cisco Secure Access Control Server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/744249" xml:lang="en">VU#744249</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21900" xml:lang="en">21900</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0068" xml:lang="en">ADV-2007-0068</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31323" xml:lang="en">cisco-acs-csadmin-bo(31323)</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in the CSAdmin service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allows remote attackers to execute arbitrary code via a crafted HTTP GET request.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0106">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.1</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.2</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.3</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.4</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0106</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:13.900-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2114" xml:lang="en">2114</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://wordpress.org/development/2007/01/wordpress-206/" xml:lang="en">http://wordpress.org/development/2007/01/wordpress-206/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.hardened-php.net/advisory_012007.140.html" xml:lang="en">http://www.hardened-php.net/advisory_012007.140.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456048/100/0/threaded" xml:lang="en">20070105 Advisory 01/2007: WordPress CSRF Protection XSS Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21893" xml:lang="en">21893</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0061" xml:lang="en">ADV-2007-0061</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the CSRF protection scheme in WordPress before 2.0.6 allows remote attackers to inject arbitrary web script or HTML via a CSRF attack with an invalid token and quote characters or HTML tags in URL variable names, which are not properly handled when WordPress generates a new link to verify the request.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0107">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0107</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:14.383-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200701-10.xml" xml:lang="en">GLSA-200701-10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2112" xml:lang="en">2112</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://wordpress.org/development/2007/01/wordpress-206/" xml:lang="en">http://wordpress.org/development/2007/01/wordpress-206/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.hardened-php.net/advisory_022007.141.html" xml:lang="en">http://www.hardened-php.net/advisory_022007.141.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>OPENPKG</vuln:source>
      <vuln:reference href="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.005.html" xml:lang="en">OpenPKG-SA-2007.005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456049/100/0/threaded" xml:lang="en">20070105 Advisory 02/2007: WordPress Trackback Charset Decoding SQL Injection Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21907" xml:lang="en">21907</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0061" xml:lang="en">ADV-2007-0061</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31297" xml:lang="en">wordpress-mbstring-security-bypass(31297)</vuln:reference>
    </vuln:references>
    <vuln:summary>WordPress before 2.0.6, when mbstring is enabled for PHP, decodes alternate character sets after escaping the SQL query, which allows remote attackers to bypass SQL injection protection schemes and execute arbitrary SQL commands via multibyte charsets, as demonstrated using UTF-7.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0108">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:novell:client:4.91:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:novell:client:4.91:sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0108</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:58.983-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017471" xml:lang="en">1017471</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2974970.htm" xml:lang="en">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2974970.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21886" xml:lang="en">21886</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0064" xml:lang="en">ADV-2007-0064</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31343" xml:lang="en">novell-profile-security-bypass(31343)</vuln:reference>
    </vuln:references>
    <vuln:summary>nwgina.dll in Novell Client 4.91 SP3 for Windows 2000/XP/2003 does not delete user profiles during a Terminal Service or Citrix session, which allows remote authenticated users to invoke alternate user profiles.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0109">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.1</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.2</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.3</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.4</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0109</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:15.150-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200701-10.xml" xml:lang="en">GLSA-200701-10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2113" xml:lang="en">2113</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455927/100/0/threaded" xml:lang="en">20070103 Wordpress &lt;= 2.x dictionnary &amp; Bruteforce attack</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0062" xml:lang="en">ADV-2007-0062</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31262" xml:lang="en">wordpress-account-enumeration(31262)</vuln:reference>
    </vuln:references>
    <vuln:summary>wp-login.php in WordPress 2.0.5 and earlier displays different error messages if a user exists or not, which allows remote attackers to obtain sensitive information and facilitates brute force attacks.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0110">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:novell:access_manager_identity_server:3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:novell:access_manager_identity_server:3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0110</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:48.813-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017483" xml:lang="en">1017483</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21921" xml:lang="en">21921</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0073" xml:lang="en">ADV-2007-0073</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://secure-support.novell.com/KanisaPlatform/Publishing/143/3615264_f.SAL_Public.html" xml:lang="en">https://secure-support.novell.com/KanisaPlatform/Publishing/143/3615264_f.SAL_Public.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in nidp/idff/sso in Novell Access Manager Identity Server before 3.0.0-1013 allows remote attackers to inject arbitrary web script or HTML via the IssueInstant parameter, which is not properly handled in the resulting error message.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0111">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:resco:photo_viewer:4.11"/>
        <cpe-lang:fact-ref name="cpe:/a:resco:photo_viewer:6.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:resco:photo_viewer:4.11</vuln:product>
      <vuln:product>cpe:/a:resco:photo_viewer:6.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0111</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:48.953-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://blog.trendmicro.com/flaw-in-3rd-party-app-weakens-windows-mobile/" xml:lang="en">http://blog.trendmicro.com/flaw-in-3rd-party-app-weakens-windows-mobile/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21920" xml:lang="en">21920</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.trendmicro.com/vinfo/secadvisories/default6.asp?VName=Vulnerability+in+Resco+Photo+Viewer+6%2E01+Enabling+Code+Injection+and+Arbitrary+Code+Execution" xml:lang="en">http://www.trendmicro.com/vinfo/secadvisories/default6.asp?VName=Vulnerability+in+Resco+Photo+Viewer+6%2E01+Enabling+Code+Injection+and+Arbitrary+Code+Execution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0072" xml:lang="en">ADV-2007-0072</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Resco Photo Viewer for PocketPC 4.11 and 6.01, as used in mobile devices running Windows Mobile 5.0, 2003, and 2003SE, allows remote attackers to execute arbitrary code via a crafted PNG image.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0112">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:createauction:createauction"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:createauction:createauction</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0112</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:15.680-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2111" xml:lang="en">2111</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456272/100/0/threaded" xml:lang="en">20070107 createauction (cats.asp) Remote SQL Injection Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21929" xml:lang="en">21929</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31356" xml:lang="en">createauction-cats-sql-injection(31356)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in cats.asp in createauction allows remote attackers to execute arbitrary SQL commands via the catid parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0113">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:packeteer:packetwise:8.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:packeteer:packetwise:8.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0113</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:16.040-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2110" xml:lang="en">2110</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456267/100/0/threaded" xml:lang="en">20070108 Packeteer PacketWise CLI overflow DoS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21933" xml:lang="en">21933</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0098" xml:lang="en">ADV-2007-0098</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31357" xml:lang="en">packetshaper-argument-dos(31357)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Packeteer PacketShaper PacketWise 8.x allows remote authenticated users to cause a denial of service (reset or reboot) via (1) a long traffic class argument to the "class show" command or (2) a long POLICY parameter value in clastree.htm.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0114">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sun:java_system_content_delivery_server:5.0::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:java_system_content_delivery_server:5.0:pu1:solaris"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:java_system_content_delivery_server:5.0::solaris</vuln:product>
      <vuln:product>cpe:/a:sun:java_system_content_delivery_server:5.0:pu1:solaris</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0114</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:59.203-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102764-1" xml:lang="en">102764</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21908" xml:lang="en">21908</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0076" xml:lang="en">ADV-2007-0076</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31345" xml:lang="en">sun-java-cds-info-disclosure(31345)</vuln:reference>
    </vuln:references>
    <vuln:summary>Sun Java System Content Delivery Server 5.0 and 5.0 PU1 allows remote attackers to obtain sensitive information regarding "content details" via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0115">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:coppermine:coppermine_photo_gallery:1.4.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:coppermine:coppermine_photo_gallery:1.4.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0115</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:16.527-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://acid-root.new.fr/poc/19070104.txt" xml:lang="en">http://acid-root.new.fr/poc/19070104.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2107" xml:lang="en">2107</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-January/001218.html" xml:lang="en">20070108 Source verify - Coppermine Photo Gallery &lt;= 1.4.10 code injection</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456051/100/0/threaded" xml:lang="en">20070105 Coppermine Photo Gallery &lt;= 1.4.10 SQL Injection Exploit</vuln:reference>
    </vuln:references>
    <vuln:summary>Static code injection vulnerability in Coppermine Photo Gallery 1.4.10 and earlier allows remote authenticated administrators to execute arbitrary PHP code via the Username to login.php, which is injected into an error message in security.log.php, which can then be accessed using viewlog.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0116">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:digger_solutions:intranet_open_source"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:digger_solutions:intranet_open_source</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0116</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:16.917-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2109" xml:lang="en">2109</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456047/100/0/threaded" xml:lang="en">20070105 Intranet Open Source Remote Password Disclosure "intranet.mdb"</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31308" xml:lang="en">intranet-intranet-info-disclosure(31308)</vuln:reference>
    </vuln:references>
    <vuln:summary>Digger Solutions Intranet Open Source (IOS) stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for data/intranet.mdb.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0117">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0117</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:49.470-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-05-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-05-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21899" xml:lang="en">21899</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0074" xml:lang="en">ADV-2007-0074</vuln:reference>
    </vuln:references>
    <vuln:summary>DiskManagementTool in the DiskManagement.framework 92.29 on Mac OS X 10.4.8 does not properly validate Bill of Materials (BOM) files, which allows attackers to gain privileges via a BOM file under /Library/Receipts/, which triggers arbitrary file permission changes upon execution of a diskutil permission repair operation.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0118">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:edittag:edittag:1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:edittag:edittag:1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0118</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:17.243-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456055/100/0/threaded" xml:lang="en">20070105 Multiple bugs in EditTag</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21890" xml:lang="en">21890</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple absolute path traversal vulnerabilities in EditTag 1.2 allow remote attackers to read arbitrary files via an absolute pathname in the file parameter to (1) edittag.cgi, (2) edittag.pl, (3) edittag_mp.cgi, or (4) edittag_mp.pl.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0119">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:edittag:edittag:1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:edittag:edittag:1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0119</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:17.667-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456055/100/0/threaded" xml:lang="en">20070105 Multiple bugs in EditTag</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21891" xml:lang="en">21891</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in EditTag 1.2 allow remote attackers to inject arbitrary web script or HTML via the plain parameter to (1) mkpw_mp.cgi, (2) mkpw.pl, or (3) mkpw.cgi.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0120">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:acunetix:web_vulnerability_scanner:4.0_build_2006-07-17"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:acunetix:web_vulnerability_scanner:4.0_build_2006-07-17</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0120</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:56.177-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>1.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21898" xml:lang="en">21898</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31279" xml:lang="en">acunetix-content-length-dos(31279)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3078" xml:lang="en">3078</vuln:reference>
    </vuln:references>
    <vuln:summary>Acunetix Web Vulnerability Scanner (WVS) 4.0 Build 20060717 and earlier allows remote attackers to cause a denial of service (application crash) via multiple HTTP requests containing invalid Content-Length values.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0121">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:michael_romedahl:ri_blog:1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:michael_romedahl:ri_blog:1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0121</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:18.040-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2108" xml:lang="en">2108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456052/100/0/threaded" xml:lang="en">20070105 RI Blog 1.3 XSS Vuln.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21880" xml:lang="en">21880</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0083" xml:lang="en">ADV-2007-0083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31317" xml:lang="en">riblog-search-xss(31317)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in search.asp in RI Blog 1.3 allows remote attackers to inject arbitrary web script or HTML via the q parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0122">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:coppermine:coppermine_photo_gallery:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:coppermine:coppermine_photo_gallery:1.0_rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:coppermine:coppermine_photo_gallery:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:coppermine:coppermine_photo_gallery:1.1_beta_2"/>
        <cpe-lang:fact-ref name="cpe:/a:coppermine:coppermine_photo_gallery:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:coppermine:coppermine_photo_gallery:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:coppermine:coppermine_photo_gallery:1.2.2_b"/>
        <cpe-lang:fact-ref name="cpe:/a:coppermine:coppermine_photo_gallery:1.2.2_b-nuke"/>
        <cpe-lang:fact-ref name="cpe:/a:coppermine:coppermine_photo_gallery:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:coppermine:coppermine_photo_gallery:1.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:coppermine:coppermine_photo_gallery:1.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:coppermine:coppermine_photo_gallery:1.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:coppermine:coppermine_photo_gallery:1.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:coppermine:coppermine_photo_gallery:1.4.9"/>
        <cpe-lang:fact-ref name="cpe:/a:coppermine:coppermine_photo_gallery:1.4.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:coppermine:coppermine_photo_gallery:1.0</vuln:product>
      <vuln:product>cpe:/a:coppermine:coppermine_photo_gallery:1.0_rc3</vuln:product>
      <vuln:product>cpe:/a:coppermine:coppermine_photo_gallery:1.1</vuln:product>
      <vuln:product>cpe:/a:coppermine:coppermine_photo_gallery:1.1_beta_2</vuln:product>
      <vuln:product>cpe:/a:coppermine:coppermine_photo_gallery:1.2</vuln:product>
      <vuln:product>cpe:/a:coppermine:coppermine_photo_gallery:1.2.1</vuln:product>
      <vuln:product>cpe:/a:coppermine:coppermine_photo_gallery:1.2.2_b</vuln:product>
      <vuln:product>cpe:/a:coppermine:coppermine_photo_gallery:1.2.2_b-nuke</vuln:product>
      <vuln:product>cpe:/a:coppermine:coppermine_photo_gallery:1.3</vuln:product>
      <vuln:product>cpe:/a:coppermine:coppermine_photo_gallery:1.3.2</vuln:product>
      <vuln:product>cpe:/a:coppermine:coppermine_photo_gallery:1.3.3</vuln:product>
      <vuln:product>cpe:/a:coppermine:coppermine_photo_gallery:1.3.4</vuln:product>
      <vuln:product>cpe:/a:coppermine:coppermine_photo_gallery:1.4.4</vuln:product>
      <vuln:product>cpe:/a:coppermine:coppermine_photo_gallery:1.4.9</vuln:product>
      <vuln:product>cpe:/a:coppermine:coppermine_photo_gallery:1.4.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0122</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:18.510-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://acid-root.new.fr/poc/19070104.txt" xml:lang="en">http://acid-root.new.fr/poc/19070104.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2123" xml:lang="en">2123</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456051/100/0/threaded" xml:lang="en">20070105 Coppermine Photo Gallery &lt;= 1.4.10 SQL Injection Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21894" xml:lang="en">21894</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3085" xml:lang="en">3085</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in Coppermine Photo Gallery 1.4.10 and earlier allow remote authenticated administrators to execute arbitrary SQL commands via (1) the cat parameter to albmgr.php, and possibly (2) the gid parameter to usermgr.php; (3) the start parameter to db_ecard.php; and the albumid parameter to unspecified files, related to the (4) filename_to_title and (5) del_titles functions.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0123">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:uber_uploader:uber_uploader:4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:uber_uploader:uber_uploader:4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0123</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:19.260-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2116" xml:lang="en">2116</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456045/100/0/threaded" xml:lang="en">20070105 Uber Uploader 4.2 Arbitrary File Upload Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31303" xml:lang="en">uber-uploader-phtml-file-upload(31303)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unrestricted file upload vulnerability in Uber Uploader 4.2 allows remote attackers to upload and execute arbitrary PHP scripts by naming them with a .phtml extension, which bypasses the .php extension check but is still executable on some server configurations.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0124">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.7"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.8"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.9"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.10"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:drupal:drupal:4.6</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.0</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.1</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.2</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.3</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.4</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.5</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.6</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.7</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.8</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.9</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.10</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.0</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.1</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.2</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.3</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0124</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:19.510-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://drupal.org/node/104238" xml:lang="en">http://drupal.org/node/104238</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2115" xml:lang="en">2115</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456056/100/0/threaded" xml:lang="en">20070105 [DRUPAL-SA-2007-002] Drupal 4.6.11 / 4.7.5 fixes DoS issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21895" xml:lang="en">21895</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0051" xml:lang="en">ADV-2007-0051</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Drupal before 4.6.11, and 4.7 before 4.7.5, when MySQL is used, allows remote authenticated users to cause a denial of service by poisoning the page cache via unspecified vectors, which triggers erroneous 404 HTTP errors for pages that exist.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0125">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:kaspersky_lab:kaspersky_antivirus_engine:5.5.10::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:kaspersky_lab:kaspersky_antivirus_engine:6.0::windows"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kaspersky_lab:kaspersky_antivirus_engine:5.5.10::linux</vuln:product>
      <vuln:product>cpe:/a:kaspersky_lab:kaspersky_antivirus_engine:6.0::windows</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0125</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:59.467-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=459" xml:lang="en">20070105 Kaspersky Antivirus Scan Engine PE File Denial of Service Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017476" xml:lang="en">1017476</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21901" xml:lang="en">21901</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0067" xml:lang="en">ADV-2007-0067</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31315" xml:lang="en">kaspersky-antivirus-pe-dos(31315)</vuln:reference>
    </vuln:references>
    <vuln:summary>Kaspersky Labs Antivirus Engine 6.0 for Windows and 5.5-10 for Linux before 20070102 enter an infinite loop upon encountering an invalid NumberOfRvaAndSizes value in the Optional Windows Header of a portable executable (PE) file, which allows remote attackers to cause a denial of service (CPU consumption) by scanning a crafted PE file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0126">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:9.02"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:opera:opera_browser:9.02</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0126</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:59.517-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=457" xml:lang="en">20070105 Opera Software Opera Web Browser JPG Image DHT Marker Heap Corruption Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0009.html" xml:lang="en">SUSE-SA:2007:009</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017473" xml:lang="en">1017473</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200701-08.xml" xml:lang="en">GLSA-200701-08</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.opera.com/support/search/supsearch.dml?index=852" xml:lang="en">http://www.opera.com/support/search/supsearch.dml?index=852</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0060" xml:lang="en">ADV-2007-0060</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31305" xml:lang="en">opera-jpeg-dht-bo(31305)</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in Opera 9.02 allows remote attackers to execute arbitrary code via a JPEG file with an invalid number of index bytes in the Define Huffman Table (DHT) marker.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0127">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:1.00"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:2.00"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:2.10"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:2.10:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:2.10:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:2.10:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:2.12"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:3.00"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:3.00:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:3.21"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:3.50"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:3.51"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:3.60"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:3.61"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:3.62"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:3.62:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:4.00"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:4.00:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:4.00:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:4.00:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:4.00:beta5"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:4.00:beta6"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:4.01"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:4.02"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:5.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:5.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:5.0:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:5.0:beta5"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:5.0:beta6"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:5.0:beta7"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:5.0:beta8"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:5.02"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:5.10"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:5.11"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:5.12"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:6.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:6.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:6.0:tp1"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:6.0:tp2"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:6.0:tp3"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:6.1:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:6.02"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:6.03"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:6.04"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:6.05"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:6.06"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:6.11"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:6.12"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.0:beta1_v2"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.01"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.02"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.03"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.10"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.10:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.11"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.11:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.20"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.20:beta7"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.21"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.22"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.23"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.50"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.50:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.51"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.52"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.53"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.54"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.54:update1"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.54:update2"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:7.60"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:8.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:8.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:8.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:8.01"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:8.02"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:8.50"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:8.51"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:8.52"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:8.53"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:8.54"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:9.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:9.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:9.01"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:9.02"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:opera:opera_browser:1.00</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:2.00</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:2.10</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:2.10:beta1</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:2.10:beta2</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:2.10:beta3</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:2.12</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:3.00</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:3.00:beta</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:3.10</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:3.21</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:3.50</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:3.51</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:3.60</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:3.61</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:3.62</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:3.62:beta</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:4.00</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:4.00:beta2</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:4.00:beta3</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:4.00:beta4</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:4.00:beta5</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:4.00:beta6</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:4.01</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:4.02</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:5.0</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:5.0:beta2</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:5.0:beta3</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:5.0:beta4</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:5.0:beta5</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:5.0:beta6</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:5.0:beta7</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:5.0:beta8</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:5.02</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:5.10</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:5.11</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:5.12</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:6.0</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:6.0:beta1</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:6.0:beta2</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:6.0:tp1</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:6.0:tp2</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:6.0:tp3</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:6.1</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:6.1:beta1</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:6.02</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:6.03</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:6.04</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:6.05</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:6.06</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:6.11</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:6.12</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.0</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.0:beta1</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.0:beta1_v2</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.0:beta2</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.01</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.02</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.03</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.10</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.10:beta1</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.11</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.11:beta2</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.20</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.20:beta7</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.21</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.22</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.23</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.50</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.50:beta1</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.51</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.52</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.53</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.54</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.54:update1</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.54:update2</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:7.60</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:8.0</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:8.0:beta1</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:8.0:beta2</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:8.0:beta3</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:8.01</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:8.02</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:8.50</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:8.51</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:8.52</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:8.53</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:8.54</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:9.0</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:9.0:beta1</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:9.0:beta2</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:9.01</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:9.02</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0127</vuln:cve-id>
    <vuln:published-datetime>2007-01-08T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-09T17:35:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=458" xml:lang="en">20070105 Opera Software Opera Web Browser createSVGTransformFromMatrix Object Typecasting Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0009.html" xml:lang="en">SUSE-SA:2007:009</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017473" xml:lang="en">1017473</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200701-08.xml" xml:lang="en">GLSA-200701-08</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.opera.com/support/search/supsearch.dml?index=851" xml:lang="en">http://www.opera.com/support/search/supsearch.dml?index=851</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0060" xml:lang="en">ADV-2007-0060</vuln:reference>
    </vuln:references>
    <vuln:summary>The Javascript SVG support in Opera before 9.10 does not properly validate object types in a createSVGTransformFromMatrix request, which allows remote attackers to execute arbitrary code via JavaScript code that uses an invalid object in this request that causes a controlled pointer to be referenced during the virtual function call.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0128">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:digiappz:digirez:3.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:digiappz:digirez:3.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0128</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:56.300-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0053" xml:lang="en">ADV-2007-0053</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3081" xml:lang="en">3081</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in info_book.asp in Digirez 3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the book_id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0129">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:locazo:locazolist_classifieds:2.01a_beta5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:locazo:locazolist_classifieds:2.01a_beta5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0129</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:56.363-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0052" xml:lang="en">ADV-2007-0052</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31242" xml:lang="en">locazolist-main-sql-injection(31242)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3073" xml:lang="en">3073</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in main.asp in LocazoList 2.01a beta5 and earlier allows remote attackers to execute arbitrary SQL commands via the subcatID parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0130">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:igeneric:ig_calendar:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:igeneric:ig_calendar:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0130</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:19.963-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456044/100/0/threaded" xml:lang="en">20070105 IG Calendar SQL Injection</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21873" xml:lang="en">21873</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0055" xml:lang="en">ADV-2007-0055</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31300" xml:lang="en">igcalendar-user-sql-injection(31300)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3082" xml:lang="en">3082</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in user.php in iGeneric iG Calendar 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0131">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:jamwiki:jamwiki:0.4.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:jamwiki:jamwiki:0.4.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0131</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:59.673-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?group_id=171441&amp;release_id=475663" xml:lang="en">http://sourceforge.net/project/shownotes.php?group_id=171441&amp;release_id=475663</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21879" xml:lang="en">21879</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31296" xml:lang="en">jamwiki-permission-security-bypass(31296)</vuln:reference>
    </vuln:references>
    <vuln:summary>JAMWiki before 0.5.0 does not properly check permissions during moves of "read-only or admin-only topics," which allows remote attackers to make unauthorized changes to the wiki.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0132">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:igeneric:ig_shop:1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:igeneric:ig_shop:1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0132</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:20.477-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://packetstormsecurity.nl/0701-exploits/igshop10-multiple.txt" xml:lang="en">http://packetstormsecurity.nl/0701-exploits/igshop10-multiple.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456043/100/0/threaded" xml:lang="en">20070105 IG Shop remote code execution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21874" xml:lang="en">21874</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0056" xml:lang="en">ADV-2007-0056</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31299" xml:lang="en">igshop-compareproduct-sql-injection(31299)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3083" xml:lang="en">3083</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in compare_product.php in iGeneric iG Shop 1.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0133">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:igeneric:ig_shop:1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:igeneric:ig_shop:1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0133</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:51.220-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0056" xml:lang="en">ADV-2007-0056</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in display_review.php in iGeneric iG Shop 1.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) user_login_cookie parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0134">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:igeneric:ig_shop:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:igeneric:ig_shop:1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:igeneric:ig_shop:1.0</vuln:product>
      <vuln:product>cpe:/a:igeneric:ig_shop:1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0134</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:21.057-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://packetstormsecurity.nl/0701-exploits/igshop10-multiple.txt" xml:lang="en">http://packetstormsecurity.nl/0701-exploits/igshop10-multiple.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-June/001664.html" xml:lang="en">20070618 Dup: iG Shop 1.4 (page.php) Remote Code Execution Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456043/100/0/threaded" xml:lang="en">20070105 IG Shop remote code execution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/471722/100/0/threaded" xml:lang="en">20070619 iG Shop 1.4 eval Inclusion Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21875" xml:lang="en">21875</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0056" xml:lang="en">ADV-2007-0056</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31301" xml:lang="en">igshop-cartpage-code-execution(31301)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3083" xml:lang="en">3083</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple eval injection vulnerabilities in iGeneric iG Shop 1.0 allow remote attackers to execute arbitrary code via the action parameter, which is supplied to an eval function call in (1) cart.php and (2) page.php.  NOTE: a later report and CVE analysis indicate that the vulnerability is present in 1.4.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0135">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:aratix:aratix:0.2.2_beta_11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:aratix:aratix:0.2.2_beta_11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0135</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:56.597-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://securityreason.com/exploitalert/1698" xml:lang="en">http://securityreason.com/exploitalert/1698</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-January/001219.html" xml:lang="en">20070108 Source verify of Aratix RFI</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0054" xml:lang="en">ADV-2007-0054</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31282" xml:lang="en">aratix-init-file-include(31282)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3079" xml:lang="en">3079</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in inc/init.inc.php in Aratix 0.2.2 beta 11 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the current_path parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0136">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:-"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.7"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.8"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.9"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.10"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.0:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.0:beta5"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.0:beta6"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.0:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:drupal:drupal:-</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.0.0</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.1.0</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.2.0</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.3.0</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.3.1</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.3.2</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.4.0</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.4.1</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.4.2</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.4.3</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.5.0</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.5.1</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.5.2</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.5.3</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.5.4</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.5.5</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.5.6</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.5.7</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.5.8</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.0</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.1</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.2</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.3</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.4</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.5</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.6</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.7</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.8</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.9</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.10</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.0</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.0:beta3</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.0:beta4</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.0:beta5</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.0:beta6</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.0:rc1</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.0:rc2</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.0:rc3</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.0:rc4</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.1</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.2</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.3</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0136</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-17T14:39:23.577-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2018-10-17T13:41:49.437-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://drupal.org/files/sa-2007-001/advisory.txt" xml:lang="en">http://drupal.org/files/sa-2007-001/advisory.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://drupal.org/node/104233" xml:lang="en">http://drupal.org/node/104233</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://marc.info/?l=full-disclosure&amp;m=116799778408115&amp;w=2" xml:lang="en">20070105 [DRUPAL-SA-2007-001] Drupal 4.6.11 / 4.7.5 fixes</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456054/100/100/threaded" xml:lang="en">20070105 [DRUPAL-SA-2007-001] Drupal 4.6.11 / 4.7.5 fixes XSS issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0050" xml:lang="en">ADV-2007-0050</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31311" xml:lang="en">drupal-core-unspecified-xss(31311)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Drupal before 4.6.11, and 4.7 before 4.7.5, allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in the (1) filter and (2) system modules.  NOTE: some of these details are obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0137">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:serendipitynz:serene_bach:1.18r"/>
        <cpe-lang:fact-ref name="cpe:/a:serendipitynz:serene_bach:2.05r"/>
        <cpe-lang:fact-ref name="cpe:/a:serendipitynz:serene_bach:2.08d"/>
        <cpe-lang:fact-ref name="cpe:/a:serendipitynz:serene_bach_sb:1.13d"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:serendipitynz:serene_bach:1.18r</vuln:product>
      <vuln:product>cpe:/a:serendipitynz:serene_bach:2.05r</vuln:product>
      <vuln:product>cpe:/a:serendipitynz:serene_bach:2.08d</vuln:product>
      <vuln:product>cpe:/a:serendipitynz:serene_bach_sb:1.13d</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0137</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:29:59.983-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>JVN</vuln:source>
      <vuln:reference href="http://jvn.jp/jp/JVN%2365500885/index.html" xml:lang="en">JVN#65500885</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017470" xml:lang="en">1017470</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://serenebach.net/log/sb119R.html" xml:lang="en">http://serenebach.net/log/sb119R.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://serenebach.net/log/sb209R.html" xml:lang="en">http://serenebach.net/log/sb209R.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21884" xml:lang="en">21884</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0065" xml:lang="en">ADV-2007-0065</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31302" xml:lang="en">serene-bach-unspecified-xss(31302)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in SimpleBoxes/SerendipityNZ Serene Bach 2.05R and earlier, and 2.08D and earlier in the 2.08 series; and (2) sb 1.13D and earlier, and 1.18R and earlier in the 1.18 series; allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0138">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:fersch:formbankserver:1.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:fersch:formbankserver:1.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0138</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:00.047-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31216" xml:lang="en">formbankserver-formbank-dos(31216)</vuln:reference>
    </vuln:references>
    <vuln:summary>formbankcgi.exe in Fersch Formbankserver 1.9, when the PATH_INFO begins with (1) AbfrageForm or (2) EingabeForm, allows remote attackers to cause a denial of service (daemon crash) via multiple requests containing many /../ sequences in the Name parameter.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0139">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:hp:openvms:7.3::openvms_vax"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openvms:7.3_2::openvms_vax"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hp:openvms:7.3::openvms_vax</vuln:product>
      <vuln:product>cpe:/a:hp:openvms:7.3_2::openvms_vax</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0139</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:51.847-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="ftp://ftp.itrc.hp.com/openvms_patches/alpha/V7.3-2/AXP_DNVOSIMUP01-V0703-2.txt" xml:lang="en">ftp://ftp.itrc.hp.com/openvms_patches/alpha/V7.3-2/AXP_DNVOSIMUP01-V0703-2.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="ftp://ftp.itrc.hp.com/openvms_patches/vax/V7.3/VAX_DNVOSIMUP01-V0703.txt" xml:lang="en">ftp://ftp.itrc.hp.com/openvms_patches/vax/V7.3/VAX_DNVOSIMUP01-V0703.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0063" xml:lang="en">ADV-2007-0063</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the DECnet-Plus 7.3-2 feature in DECnet/OSI 7.3-2 for OpenVMS ALPHA, and the DECnet-Plus 7.3 feature in DECnet/OSI 7.3 for OpenVMS VAX, allows attackers to obtain "unintended privileged access to data and system resources" via unspecified vectors, related to (1) [SYSEXE]CTF$UI.EXE, (2) [SYSMSG]CTF$MESSAGES.EXE, (3) [SYSHLP]CTF$HELP.HLB, and (4) [SYSMGR]CTF$STARTUP.COM.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0140">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:kolayindir_download:kolayindir_download"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kolayindir_download:kolayindir_download</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0140</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:22.587-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2122" xml:lang="en">2122</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456068/100/0/threaded" xml:lang="en">20070105 Kolayindir Download (Yenionline) (tr) SqL Injection Vuln.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21889" xml:lang="en">21889</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0079" xml:lang="en">ADV-2007-0079</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31320" xml:lang="en">kolayindirdownload-down-sql-injection(31320)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in down.asp in Kolayindir Download (Yenionline) allows remote attackers to execute arbitrary SQL commands via the id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0141">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:yet_another_link_directory:yet_another_link_directory:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:yet_another_link_directory:yet_another_link_directory:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0141</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:23.087-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2121" xml:lang="en">2121</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456122/100/0/threaded" xml:lang="en">20070106 Yet Another Link Directory v1.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21904" xml:lang="en">21904</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0082" xml:lang="en">ADV-2007-0082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31322" xml:lang="en">yald-yald-xss(31322)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in yald.php in Yet Another Link Directory 1.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0142">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:shopstorenow:e-commerce_shopping_cart"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:shopstorenow:e-commerce_shopping_cart</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0142</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:23.587-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2120" xml:lang="en">2120</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456127/100/0/threaded" xml:lang="en">20070106 shopstorenow (orange.asp) sql injection</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21905" xml:lang="en">21905</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0080" xml:lang="en">ADV-2007-0080</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31313" xml:lang="en">shopstorenow-orange-sql-injection(31313)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in orange.asp in ShopStoreNow E-commerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the CatID parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0143">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nune:news_script:2.0_pre2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nune:news_script:2.0_pre2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0143</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:24.087-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456242/100/0/threaded" xml:lang="en">20070107 NUNE News Script (custom_admin_path) Remote File Include Vulnerablity</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0078" xml:lang="en">ADV-2007-0078</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31312" xml:lang="en">nune-index-archives-file-include(31312)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3090" xml:lang="en">3090</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple PHP remote file inclusion vulnerabilities in NUNE News Script 2.0pre2 allow remote attackers to execute arbitrary PHP code via a URL in the custom_admin_path parameter to (1) index.php or (2) archives.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0144">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:digitizing_quote_and_ordering_system:digitizing_quote_and_ordering_system:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:digitizing_quote_and_ordering_system:digitizing_quote_and_ordering_system:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0144</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:56.707-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31321" xml:lang="en">qos-search-xss(31321)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3089" xml:lang="en">3089</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the ordernum parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0145">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bingo_news:bingo_news:3.01"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bingo_news:bingo_news:3.01</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0145</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:00.390-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017477" xml:lang="en">1017477</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31328" xml:lang="en">bingo-bnsmrep1-file-include(31328)</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in bn_smrep1.php in BinGoPHP News (BP News) 3.01 allows remote attackers to execute arbitrary PHP code via a URL in the bnrep parameter, a different vector than CVE-2006-4648 and CVE-2006-4649.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0146">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:fix_and_chips_computer_services:fix_and_chips_cms:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:fix_and_chips_computer_services:fix_and_chips_cms:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0146</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:24.603-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2119" xml:lang="en">2119</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456121/100/0/threaded" xml:lang="en">20070106 Fix &amp; Chips CMS v1.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0081" xml:lang="en">ADV-2007-0081</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31319" xml:lang="en">fixandchips-multiple-scripts-xss(31319)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Fix and Chips CMS 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in (a) delete-announce.php; the (2) Announcement form field in (b) staff.php; the (3) Client Name, (4) Business Name, (5) Street, (6) Address 2, (7) Town/City, (8) Postcode, (9) Phone Number, (10) Email Address and (11) Website Address form fields in (c) new_customer.php; and unspecified fields in (d) search.php and (e) client-results.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0147">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cuyahoga:cuyahoga:1.0.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cuyahoga:cuyahoga:1.0.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0147</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:38:59.813-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://cuyahoga.svn.sourceforge.net/viewvc/cuyahoga?view=rev&amp;revision=551" xml:lang="en">http://cuyahoga.svn.sourceforge.net/viewvc/cuyahoga?view=rev&amp;revision=551</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.cuyahoga-project.org/10/section.aspx/61" xml:lang="en">http://www.cuyahoga-project.org/10/section.aspx/61</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21927" xml:lang="en">21927</vuln:reference>
    </vuln:references>
    <vuln:summary>Cuyahoga before 1.0.1 installs the FCKEditor component with an incorrect deny statement in a Web.config file, which allows remote attackers to upload files when these privileges were intended only for the Administrator and Editor roles.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0148">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:omnigroup:omniweb:5.5.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:omnigroup:omniweb:5.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0148</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:25.260-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://blog.omnigroup.com/2007/01/07/omniweb-552-now-available-and-more-secure/" xml:lang="en">http://blog.omnigroup.com/2007/01/07/omniweb-552-now-available-and-more-secure/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-07-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-07-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.digitalmunition.com/DMA%5B2007-0107a%5D.txt" xml:lang="en">http://www.digitalmunition.com/DMA%5B2007-0107a%5D.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.omnigroup.com/applications/omniweb/releasenotes/" xml:lang="en">http://www.omnigroup.com/applications/omniweb/releasenotes/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456578/100/0/threaded" xml:lang="en">20070111 DMA[2007-0107a] OmniWeb Javascript Alert Format String Vulnerabiity and DMA[2007-0109a] Apple Finder Disk Image Volume Label Overflow / DoS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21911" xml:lang="en">21911</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0075" xml:lang="en">ADV-2007-0075</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31324" xml:lang="en">omniweb-alert-format-string(31324)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3098" xml:lang="en">3098</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in OmniGroup OmniWeb 5.5.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via format string specifiers in the Javascript alert function.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0149">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ememberspro:ememberspro:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ememberspro:ememberspro:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0149</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:25.993-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2118" xml:lang="en">2118</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456228/100/0/threaded" xml:lang="en">20070107 EMembersPro 1.0 Remote Password Disclosure Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31329" xml:lang="en">ememberspro-users-info-disclosure(31329)</vuln:reference>
    </vuln:references>
    <vuln:summary>EMembersPro 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for users.mdb.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0150">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:dayfox_designs:dayfox_blog:4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:dayfox_designs:dayfox_blog:4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0150</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:26.307-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2117" xml:lang="en">2117</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456212/100/0/threaded" xml:lang="en">20070107 Dayfox Blog Remote File Include Vuln.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0099" xml:lang="en">ADV-2007-0099</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31336" xml:lang="en">dayfoxblog-index-file-include(31336)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple PHP remote file inclusion vulnerabilities in index.php in Dayfox Blog allow remote attackers to execute arbitrary PHP code via a URL in the (1) page, (2) subject, and (3) q parameters.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0151">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mitisoft:mitisoft"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mitisoft:mitisoft</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0151</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:26.697-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456230/100/0/threaded" xml:lang="en">20070107 MitiSoft Remote Password Disclosure Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31341" xml:lang="en">mitisoft-mitisoft-info-disclosure(31341)</vuln:reference>
    </vuln:references>
    <vuln:summary>MitiSoft stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for access_MS/MitiSoft.mdb.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0152">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ohhasp:ohhasp"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ohhasp:ohhasp</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0152</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:26.930-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://64.38.62.221/ariasecucom/forum/showthread.php?t=89" xml:lang="en">http://64.38.62.221/ariasecucom/forum/showthread.php?t=89</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456117/100/0/threaded" xml:lang="en">20070106 ohhASP Remote Password Disclosure</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31342" xml:lang="en">ohhasp-ohhasp-info-disclosure(31342)</vuln:reference>
    </vuln:references>
    <vuln:summary>OhhASP stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db/OhhASP.mdb.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0153">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:adam_jarret:ajlogin:3.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adam_jarret:ajlogin:3.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0153</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:27.227-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2127" xml:lang="en">2127</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456226/100/0/threaded" xml:lang="en">20070107 AJLogin v3.5 Remote Password Disclosure Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31331" xml:lang="en">ajlogin-ajlogin-info-disclosure(31331)</vuln:reference>
    </vuln:references>
    <vuln:summary>AJLogin 3.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for ajlogin.mdb.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0154">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:webulas:webulas"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:webulas:webulas</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0154</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:27.510-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2126" xml:lang="en">2126</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456239/100/0/threaded" xml:lang="en">20070107 Webulas Remote Password Disclosure Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31338" xml:lang="en">webulas-db-info-disclosure(31338)</vuln:reference>
    </vuln:references>
    <vuln:summary>Webulas stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db/db.mdb.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0155">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:harikaonline:harikaonline:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:harikaonline:harikaonline:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0155</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:27.807-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2125" xml:lang="en">2125</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456238/100/0/threaded" xml:lang="en">20070107 HarikaOnline v2.0 Remote Password Disclosure Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31339" xml:lang="en">harikaonline-harikaonline-info-disclosure(31339)</vuln:reference>
    </vuln:references>
    <vuln:summary>HarikaOnline 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for harikaonline.mdb.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0156">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:m-core:m-core"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:m-core:m-core</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0156</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:28.103-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2124" xml:lang="en">2124</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456235/100/0/threaded" xml:lang="en">20070107 M-Core Remote Password Disclosure Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31340" xml:lang="en">mcore-uyelik-info-disclosure(31340)</vuln:reference>
    </vuln:references>
    <vuln:summary>M-Core stores the database under the web document root, which allows remote attackers to obtain sensitive information via a direct request to db/uyelik.mdb.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0157">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:neon:neon:0.26.0"/>
        <cpe-lang:fact-ref name="cpe:/a:neon:neon:0.26.1"/>
        <cpe-lang:fact-ref name="cpe:/a:neon:neon:0.26.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:neon:neon:0.26.0</vuln:product>
      <vuln:product>cpe:/a:neon:neon:0.26.1</vuln:product>
      <vuln:product>cpe:/a:neon:neon:0.26.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0157</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:53.487-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi/neon26_0.26.2-3_to_mdx1.diff?bug=404723;msg=5;att=2" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi/neon26_0.26.2-3_to_mdx1.diff?bug=404723;msg=5;att=2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=404723" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=404723</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://mailman.webdav.org/pipermail/cadaver/2007-January/001015.html" xml:lang="en">[cadaver] 20070123 release 0.22.5</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://mailman.webdav.org/pipermail/neon/2007-January/002362.html" xml:lang="en">[neon] 20070107 invalid chars cause sigserv in neon</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:013" xml:lang="en">MDKSA-2007:013</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_02_sr.html" xml:lang="en">SUSE-SR:2007:002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22035" xml:lang="en">22035</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0172" xml:lang="en">ADV-2007-0172</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0362" xml:lang="en">ADV-2007-0362</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.webdav.org/cadaver/" xml:lang="en">http://www.webdav.org/cadaver/</vuln:reference>
    </vuln:references>
    <vuln:summary>Array index error in the uri_lookup function in the URI parser for neon 0.26.0 to 0.26.2, possibly only on 64-bit platforms, allows remote malicious servers to cause a denial of service (crash) via a URI with non-ASCII characters, which triggers a buffer under-read due to a type conversion error that generates a negative index.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0159">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:geoip:geoip:1.4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:geoip:geoip:1.4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0159</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:01.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://arctic.org/~dean/patches/GeoIP-1.4.0-update-vulnerability.patch" xml:lang="en">http://arctic.org/~dean/patches/GeoIP-1.4.0-update-vulnerability.patch</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:004" xml:lang="en">MDKSA-2007:004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21959" xml:lang="en">21959</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-412-1" xml:lang="en">USN-412-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0117" xml:lang="en">ADV-2007-0117</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0118" xml:lang="en">ADV-2007-0118</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31383" xml:lang="en">geoip-geoipupdate-directory-traversal(31383)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in the GeoIP_update_database_general function in libGeoIP/GeoIPUpdate.c in GeoIP 1.4.0 allows remote malicious update servers (possibly only update.maxmind.com) to overwrite arbitrary files via a .. (dot dot) in the database filename, which is returned by a request to app/update_getfilename.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0160">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:centericq:centericq:4.9.11"/>
        <cpe-lang:fact-ref name="cpe:/a:centericq:centericq:4.9.12"/>
        <cpe-lang:fact-ref name="cpe:/a:centericq:centericq:4.12"/>
        <cpe-lang:fact-ref name="cpe:/a:centericq:centericq:4.13"/>
        <cpe-lang:fact-ref name="cpe:/a:centericq:centericq:4.14"/>
        <cpe-lang:fact-ref name="cpe:/a:centericq:centericq:4.20"/>
        <cpe-lang:fact-ref name="cpe:/a:centericq:centericq:4.21"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:centericq:centericq:4.9.11</vuln:product>
      <vuln:product>cpe:/a:centericq:centericq:4.9.12</vuln:product>
      <vuln:product>cpe:/a:centericq:centericq:4.12</vuln:product>
      <vuln:product>cpe:/a:centericq:centericq:4.13</vuln:product>
      <vuln:product>cpe:/a:centericq:centericq:4.14</vuln:product>
      <vuln:product>cpe:/a:centericq:centericq:4.20</vuln:product>
      <vuln:product>cpe:/a:centericq:centericq:4.21</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0160</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:28.383-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2129" xml:lang="en">2129</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017545" xml:lang="en">1017545</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200701-20.xml" xml:lang="en">GLSA-200701-20</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456255/100/0/threaded" xml:lang="en">20070107 TK53 Advisory #1: CenterICQ remote DoS buffer overflow in LiveJournal handling</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21932" xml:lang="en">21932</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0306" xml:lang="en">ADV-2007-0306</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31330" xml:lang="en">centericq-username-bo(31330)</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in the LiveJournal support (hooks/ljhook.cc) in CenterICQ 4.9.11 through 4.21.0, when using unofficial LiveJournal servers, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by adding the victim as a friend and using long (1) username and (2) real name strings.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0161">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:hp:pml_driver_hpz12"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:hp:color_laserjet_4650"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:officejet_4100"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:officejet_5100"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:officejet_5500"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:officejet_6100"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:officejet_7100"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:officejet_d"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:officejet_g"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:officejet_k"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:psc_1100"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:psc_1200"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:psc_1210_all-in-one"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:psc_1300"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:psc_2100"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:psc_2200"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:psc_2400_photosmart_all-in-one"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:psc_2500_photosmart_all-in-one"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:psc_2510_photosmart"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:psc_700"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:psc_900"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hp:pml_driver_hpz12</vuln:product>
      <vuln:product>cpe:/h:hp:color_laserjet_4650</vuln:product>
      <vuln:product>cpe:/h:hp:officejet_4100</vuln:product>
      <vuln:product>cpe:/h:hp:officejet_5100</vuln:product>
      <vuln:product>cpe:/h:hp:officejet_5500</vuln:product>
      <vuln:product>cpe:/h:hp:officejet_6100</vuln:product>
      <vuln:product>cpe:/h:hp:officejet_7100</vuln:product>
      <vuln:product>cpe:/h:hp:officejet_d</vuln:product>
      <vuln:product>cpe:/h:hp:officejet_g</vuln:product>
      <vuln:product>cpe:/h:hp:officejet_k</vuln:product>
      <vuln:product>cpe:/h:hp:psc_1100</vuln:product>
      <vuln:product>cpe:/h:hp:psc_1200</vuln:product>
      <vuln:product>cpe:/h:hp:psc_1210_all-in-one</vuln:product>
      <vuln:product>cpe:/h:hp:psc_1300</vuln:product>
      <vuln:product>cpe:/h:hp:psc_2100</vuln:product>
      <vuln:product>cpe:/h:hp:psc_2200</vuln:product>
      <vuln:product>cpe:/h:hp:psc_2400_photosmart_all-in-one</vuln:product>
      <vuln:product>cpe:/h:hp:psc_2500_photosmart_all-in-one</vuln:product>
      <vuln:product>cpe:/h:hp:psc_2510_photosmart</vuln:product>
      <vuln:product>cpe:/h:hp:psc_700</vuln:product>
      <vuln:product>cpe:/h:hp:psc_900</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0161</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:28.963-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2128" xml:lang="en">2128</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secway.org/advisory/AD20070108.txt" xml:lang="en">http://secway.org/advisory/AD20070108.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456259/100/0/threaded" xml:lang="en">20070108 HP Multiple Products PML Driver Local Privilege Escalation</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21935" xml:lang="en">21935</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0094" xml:lang="en">ADV-2007-0094</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31361" xml:lang="en">pml-driver-config-privilege-escalation(31361)</vuln:reference>
    </vuln:references>
    <vuln:summary>The PML Driver HPZ12 (HPZipm12.exe) in the HP all-in-one drivers, as used by multiple HP products, uses insecure SERVICE_CHANGE_CONFIG DACL permissions, which allows local users to gain privileges and execute arbitrary programs, as demonstrated by modifying the binpath argument, a related issue to CVE-2006-0023.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0162">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:unsanity:application_enhancer:2.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:unsanity:application_enhancer:2.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0162</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:01.187-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://landonf.bikemonkey.org/code/macosx/MOAB_Day_8.20070109002959.18582.timor.html" xml:lang="en">http://landonf.bikemonkey.org/code/macosx/MOAB_Day_8.20070109002959.18582.timor.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-08-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-08-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21951" xml:lang="en">21951</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31349" xml:lang="en">ape-appenhancer-privilege-escalation(31349)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unsanity Application Enhancer (APE) 2.0.2 installs with insecure permissions for the (1) ApplicationEnhancer binary and the (2) /Library/Frameworks/ApplicationEnhancer.framework directory, which allows local users to gain privileges by modifying or replacing the binary or library files.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0163">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:securekit:securekit_steganography:1.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:securekit:securekit_steganography:1.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:securekit:securekit_steganography:1.7.1</vuln:product>
      <vuln:product>cpe:/a:securekit:securekit_steganography:1.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0163</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:29.540-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://homepage.mac.com/adonismac/Advisory/steg/steganography.html" xml:lang="en">http://homepage.mac.com/adonismac/Advisory/steg/steganography.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456283/100/0/threaded" xml:lang="en">20070106 Cracking Steganography Application in less than ONE minute</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456519/100/0/threaded" xml:lang="en">20070107 A Major design Bug in Steganography 1.7.x, 1.8 (latest) (Updated Version)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31378" xml:lang="en">steganography-password-security-bypass(31378)</vuln:reference>
    </vuln:references>
    <vuln:summary>SecureKit Steganography 1.7.1 and 1.8 embeds password information in the carrier file, which allows remote attackers to bypass authentication requirements and decrypt embedded steganography by replacing the last 20 bytes of the JPEG image with alternate password information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0164">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:camouflage:camouflage:1.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:camouflage:camouflage:1.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0164</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:29.993-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://homepage.mac.com/adonismac/Advisory/steg/camouflage.html" xml:lang="en">http://homepage.mac.com/adonismac/Advisory/steg/camouflage.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456541/100/0/threaded" xml:lang="en">20070107 A Major design Bug in Camouflage 1.2.1 (latest)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21939" xml:lang="en">21939</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31375" xml:lang="en">camouflage-password-security-bypass(31375)</vuln:reference>
    </vuln:references>
    <vuln:summary>Camouflage 1.2.1 embeds password information in the carrier file, which allows remote attackers to bypass authentication requirements and decrypt embedded steganography by replacing certain bytes of the JPEG image with alternate password information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0165">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0165</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:37.090-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2210" name="oval:org.mitre.oval:def:2210"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5920" name="oval:org.mitre.oval:def:5920"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017492" xml:lang="en">1017492</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102713-1" xml:lang="en">102713</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2007-036.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2007-036.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21964" xml:lang="en">21964</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0110" xml:lang="en">ADV-2007-0110</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31366" xml:lang="en">solaris-rpcbind-dos(31366)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in libnsl in Sun Solaris 8 and 9 allows remote attackers to cause a denial of service (crash) via malformed RPC requests that trigger a crash in rpcbind.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0166">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:6.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:freebsd:freebsd:5.3</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:6.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0166</vuln:cve-id>
    <vuln:published-datetime>2007-01-11T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:39:05.280-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FREEBSD</vuln:source>
      <vuln:reference href="http://security.freebsd.org/advisories/FreeBSD-SA-07:01.jail.asc" xml:lang="en">FreeBSD-SA-07:01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017505" xml:lang="en">1017505</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22011" xml:lang="en">22011</vuln:reference>
    </vuln:references>
    <vuln:summary>The jail rc.d script in FreeBSD 5.3 up to 6.2 does not verify pathnames when writing to /var/log/console.log during a jail start-up, or when file systems are mounted or unmounted, which allows local root users to overwrite arbitrary files, or mount/unmount files, outside of the jail via a symlink attack.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0167">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ppc_search_engine:ppc_search_engine:1.61"/>
        <cpe-lang:fact-ref name="cpe:/a:wgs-ppc:wgs-ppc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ppc_search_engine:ppc_search_engine:1.61</vuln:product>
      <vuln:product>cpe:/a:wgs-ppc:wgs-ppc</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0167</vuln:cve-id>
    <vuln:published-datetime>2007-01-09T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:30.417-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2134" xml:lang="en">2134</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-January/001221.html" xml:lang="en">20070109 "ppc engine" is WGS-PPC</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456386/100/0/threaded" xml:lang="en">20070109 ppc engine Multiple file inclusion</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21961" xml:lang="en">21961</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31355" xml:lang="en">demoppc-inc-file-include(31355)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3104" xml:lang="en">3104</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple PHP file inclusion vulnerabilities in WGS-PPC (aka PPC Search Engine), as distributed with other aliases, allow remote attackers to execute arbitrary PHP code via a URL in the INC parameter in (1) config_admin.php, (2) config_main.php, (3) config_member.php, and (4) mysql_config.php in config/; (5) admin.php and (6) index.php in admini/; (7) paypalipn/ipnprocess.php; (8) index.php and (9) registration.php in members/; and (10) ppcbannerclick.php and (11) ppcclick.php in main/.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0168">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ca:brightstor_arcserve_backup:9.01"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:brightstor_arcserve_backup:11.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:brightstor_enterprise_backup:10.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:business_protection_suite:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ca:brightstor_arcserve_backup:9.01</vuln:product>
      <vuln:product>cpe:/a:ca:brightstor_arcserve_backup:11.5</vuln:product>
      <vuln:product>cpe:/a:ca:brightstor_enterprise_backup:10.5</vuln:product>
      <vuln:product>cpe:/a:ca:business_protection_suite:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0168</vuln:cve-id>
    <vuln:published-datetime>2007-01-11T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:31.603-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://livesploit.com/advisories/LS-20061002.pdf" xml:lang="en">http://livesploit.com/advisories/LS-20061002.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017506" xml:lang="en">1017506</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://supportconnectw.ca.com/public/storage/infodocs/babimpsec-notice.asp" xml:lang="en">http://supportconnectw.ca.com/public/storage/infodocs/babimpsec-notice.asp</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/662400" xml:lang="en">VU#662400</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.lssec.com/advisories/LS-20061002.pdf" xml:lang="en">http://www.lssec.com/advisories/LS-20061002.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456616/100/0/threaded" xml:lang="en">20070111 ZDI-07-002: CA BrightStor ARCserve Backup Tape Engine Code Execution Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456637" xml:lang="en">20070111 LS-20061002 - Computer Associates BrightStor ARCserve Backup Remote Code Execution Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456711" xml:lang="en">20070111 [CAID 34955, 34956, 34957, 34958, 34959, 34817]: CA BrightStor ARCserve Backup Multiple Overflow Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22010" xml:lang="en">22010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0154" xml:lang="en">ADV-2007-0154</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-07-002.html" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-07-002.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31442" xml:lang="en">brightstor-tapeengine-code-execution(31442)</vuln:reference>
    </vuln:references>
    <vuln:summary>The Tape Engine service in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Server/Business Protection Suite r2 allows remote attackers to execute arbitrary code via certain data in opnum 0xBF in an RPC request, which is directly executed.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0169">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ca:brightstor_arcserve_backup:9.01"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:brightstor_arcserve_backup:11.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:brightstor_enterprise_backup:10.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:business_protection_suite:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ca:brightstor_arcserve_backup:9.01</vuln:product>
      <vuln:product>cpe:/a:ca:brightstor_arcserve_backup:11.5</vuln:product>
      <vuln:product>cpe:/a:ca:brightstor_enterprise_backup:10.5</vuln:product>
      <vuln:product>cpe:/a:ca:business_protection_suite:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0169</vuln:cve-id>
    <vuln:published-datetime>2007-01-11T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:32.573-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=467" xml:lang="en">20070111 Computer Associates BrightStor ARCserve Backup RPC Engine PFC Request Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017506" xml:lang="en">1017506</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://supportconnectw.ca.com/public/storage/infodocs/babimpsec-notice.asp" xml:lang="en">http://supportconnectw.ca.com/public/storage/infodocs/babimpsec-notice.asp</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/151032" xml:lang="en">VU#151032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/180336" xml:lang="en">VU#180336</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456618/100/0/threaded" xml:lang="en">20070111 ZDI-07-004: CA BrightStor ARCserve Backup Tape Engine Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456619/100/0/threaded" xml:lang="en">20070111 ZDI-07-003: CA BrightStor ARCserve Backup Message Engine Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456711" xml:lang="en">20070111 [CAID 34955, 34956, 34957, 34958, 34959, 34817]: CA BrightStor ARCserve Backup Multiple Overflow Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22005" xml:lang="en">22005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22006" xml:lang="en">22006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0154" xml:lang="en">ADV-2007-0154</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-07-003.html" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-07-003.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-07-004.html" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-07-004.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31433" xml:lang="en">brightstor-tapeengine-rpc-bo(31433)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31443" xml:lang="en">brightstor-messageengine-rpc-bo(31443)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Server/Business Protection Suite r2 allow remote attackers to execute arbitrary code via RPC requests with crafted data for opnums (1) 0x2F and (2) 0x75 in the (a) Message Engine RPC service, or opnum (3) 0xCF in the Tape Engine service.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0170">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:allmyphp:allmyvisitors:0.4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:allmyphp:allmyvisitors:0.4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0170</vuln:cve-id>
    <vuln:published-datetime>2007-01-10T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:56.877-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21917" xml:lang="en">21917</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31316" xml:lang="en">allmyvisitors-index-file-include(31316)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3097" xml:lang="en">3097</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in index.php in AllMyVisitors 0.4.0 allows remote attackers to execute arbitrary PHP code via a URL in the AMV_serverpath parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0171">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:voice_of_web:allmylinks:0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:voice_of_web:allmylinks:0.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:voice_of_web:allmylinks:0.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:voice_of_web:allmylinks:0.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:voice_of_web:allmylinks:0.4.9"/>
        <cpe-lang:fact-ref name="cpe:/a:voice_of_web:allmylinks:0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:voice_of_web:allmylinks:0.4</vuln:product>
      <vuln:product>cpe:/a:voice_of_web:allmylinks:0.4.1</vuln:product>
      <vuln:product>cpe:/a:voice_of_web:allmylinks:0.4.3</vuln:product>
      <vuln:product>cpe:/a:voice_of_web:allmylinks:0.4.4</vuln:product>
      <vuln:product>cpe:/a:voice_of_web:allmylinks:0.4.9</vuln:product>
      <vuln:product>cpe:/a:voice_of_web:allmylinks:0.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0171</vuln:cve-id>
    <vuln:published-datetime>2007-01-10T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:56.940-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21916" xml:lang="en">21916</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31314" xml:lang="en">allmylinks-index-file-include(31314)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3096" xml:lang="en">3096</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in index.php in AllMyLinks 0.5.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AML_opensite parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0172">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:voice_of_web:allmyguests:0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:voice_of_web:allmyguests:0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0172</vuln:cve-id>
    <vuln:published-datetime>2007-01-10T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:56.987-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21918" xml:lang="en">21918</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31310" xml:lang="en">allmyguests-multiple-file-include(31310)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3093" xml:lang="en">3093</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple PHP remote file inclusion vulnerabilities in AllMyGuests 0.3.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the AMG_serverpath parameter to (1) comments.php and (2) signin.php; and possibly via a URL in unspecified parameters to (3) include/submit.inc.php, (4) admin/index.php, (5) include/cm_submit.inc.php, and (6) index.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0173">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:l2j:statistik_script:0.09"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:l2j:statistik_script:0.09</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0173</vuln:cve-id>
    <vuln:published-datetime>2007-01-10T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:57.050-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21914" xml:lang="en">21914</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0097" xml:lang="en">ADV-2007-0097</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31309" xml:lang="en">l2j-statistik-index-file-include(31309)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3091" xml:lang="en">3091</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in index.php in L2J Statistik Script 0.09 and earlier, when register_globals is enabled and magic_quotes is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0174">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sina:sina:uc2006"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sina:sina:uc2006</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0174</vuln:cve-id>
    <vuln:published-datetime>2007-01-10T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:33.853-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://marc.info/?l=full-disclosure&amp;m=116832852700467&amp;w=2" xml:lang="en">20070109 Sina UC ActiveX Multiple Remote Stack Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secway.org/advisory/ad20070109EN.txt" xml:lang="en">http://secway.org/advisory/ad20070109EN.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456378/100/0/threaded" xml:lang="en">20070109 Sina UC ActiveX Multiple Remote Stack Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21958" xml:lang="en">21958</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0093" xml:lang="en">ADV-2007-0093</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31348" xml:lang="en">sinauc-sendchatroomopt-bo(31348)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31350" xml:lang="en">sinauc-senddownloadfile-bo(31350)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple stack-based multiple buffer overflows in the BRWOSSRE2UC.dll ActiveX Control in Sina UC2006 and earlier allow remote attackers to execute arbitrary code via a long string in the (1) astrVerion parameter to the SendChatRoomOpt function or (2) the astrDownDir parameter to the SendDownLoadFile function.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0175">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:b2evolution:b2evolution:1.8.2"/>
        <cpe-lang:fact-ref name="cpe:/a:b2evolution:b2evolution:1.8.5"/>
        <cpe-lang:fact-ref name="cpe:/a:b2evolution:b2evolution:1.8.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:b2evolution:b2evolution:1.8.2</vuln:product>
      <vuln:product>cpe:/a:b2evolution:b2evolution:1.8.5</vuln:product>
      <vuln:product>cpe:/a:b2evolution:b2evolution:1.8.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0175</vuln:cve-id>
    <vuln:published-datetime>2007-01-10T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:01.923-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=410568" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=410568</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2008/dsa-1568" xml:lang="en">DSA-1568</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21953" xml:lang="en">21953</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31368" xml:lang="en">b2evolution-login-xss(31368)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in htsrv/login.php in b2evolution 1.8.6 allows remote attackers to inject arbitrary web script or HTML via scriptable attributes in the redirect_to parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0176">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gforge:gforge:4.5.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gforge:gforge:4.5.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0176</vuln:cve-id>
    <vuln:published-datetime>2007-01-10T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:34.527-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2133" xml:lang="en">2133</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017482" xml:lang="en">1017482</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2008/dsa-1475" xml:lang="en">DSA-1475</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.eazel.es/advisory006-gforge-cross-site-scripting-vulnerability.html" xml:lang="en">http://www.eazel.es/advisory006-gforge-cross-site-scripting-vulnerability.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456296/100/0/threaded" xml:lang="en">20070108 GForge Cross Site Scripting vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21946" xml:lang="en">21946</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31346" xml:lang="en">gforge-words-xss(31346)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in search/advanced_search.php in GForge 4.5.11 allows remote attackers to inject arbitrary web script or HTML via the words parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0177">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.5_r14348"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.8.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.9.0:rc2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.4</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.5</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.5_r14348</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.6</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.7.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.7.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.8.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.8.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.8.2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.9.0:rc2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0177</vuln:cve-id>
    <vuln:published-datetime>2007-01-10T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:02.047-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/forum/forum.php?forum_id=652721" xml:lang="en">http://sourceforge.net/forum/forum.php?forum_id=652721</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_6_9/phase3/RELEASE-NOTES" xml:lang="en">http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_6_9/phase3/RELEASE-NOTES</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_7_2/phase3/RELEASE-NOTES" xml:lang="en">http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_7_2/phase3/RELEASE-NOTES</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_8_3/phase3/RELEASE-NOTES" xml:lang="en">http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_8_3/phase3/RELEASE-NOTES</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_9_0RC2/phase3/RELEASE-NOTES" xml:lang="en">http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_9_0RC2/phase3/RELEASE-NOTES</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_6_sr.html" xml:lang="en">SUSE-SR:2007:006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21956" xml:lang="en">21956</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0096" xml:lang="en">ADV-2007-0096</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31359" xml:lang="en">mediawiki-ajax-unspecified-xss(31359)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the AJAX module in MediaWiki before 1.6.9, 1.7 before 1.7.2, 1.8 before 1.8.3, and 1.9 before 1.9.0rc2, when wgUseAjax is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0178">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:php_web_scripts:easy_banner_pro:2.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php_web_scripts:easy_banner_pro:2.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0178</vuln:cve-id>
    <vuln:published-datetime>2007-01-10T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:35.167-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2132" xml:lang="en">2132</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456404/100/0/threaded" xml:lang="en">20070108 Easy Banner Pro Version 2.8 &lt;= Remote File Inclusion</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21967" xml:lang="en">21967</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31374" xml:lang="en">easybannerpro-info-file-include(31374)</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in info.php in Easy Banner Pro 2.8 allows remote attackers to execute arbitrary PHP code via a URL in the s[phppath] parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0179">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpkit:phpkit:1.6.1:rc2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpkit:phpkit:1.6.1:rc2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0179</vuln:cve-id>
    <vuln:published-datetime>2007-01-10T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:35.510-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2131" xml:lang="en">2131</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456384/100/0/threaded" xml:lang="en">20070109 Re: PHPKit 1.6.1 RC2 (faq/faq.php) Remote SQL Injection Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21962" xml:lang="en">21962</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in comment.php in PHPKIT 1.6.1 R2 allows remote attackers to execute arbitrary SQL commands via the subid parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0180">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ef_software:ef_commander:5.75"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ef_software:ef_commander:5.75</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0180</vuln:cve-id>
    <vuln:published-datetime>2007-01-10T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:02.157-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://vuln.sg/efcommander575-en.html" xml:lang="en">http://vuln.sg/efcommander575-en.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21969" xml:lang="en">21969</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31365" xml:lang="en">efcommander-iso-pathname-bo(31365)</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in EF Commander 5.75 allows user-assisted attackers to execute arbitrary code via a crafted ISO file containing a file within several nested directories, which produces a large filename that triggers the overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0181">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:scriptaty:magic_photo_storage_website"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:scriptaty:magic_photo_storage_website</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0181</vuln:cve-id>
    <vuln:published-datetime>2007-01-10T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:35.743-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456264/100/0/threaded" xml:lang="en">20070108 magic photo storage website Remote File Inclusion</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21965" xml:lang="en">21965</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0136" xml:lang="en">ADV-2007-0136</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31347" xml:lang="en">magicphotostorage-config-file-include(31347)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3100" xml:lang="en">3100</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in include/common_function.php in magic photo storage website allows remote attackers to execute arbitrary PHP code via a URL in the _config[site_path] parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0182">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:scriptaty:magic_photo_storage_website"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:scriptaty:magic_photo_storage_website</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0182</vuln:cve-id>
    <vuln:published-datetime>2007-01-12T00:04:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:36.227-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2136" xml:lang="en">2136</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456389/100/0/threaded" xml:lang="en">20070108 magic photo storage website Multiple Remote File Inclusion</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21965" xml:lang="en">21965</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbitrary PHP code via a URL in the _config[site_path] parameter to (1) admin_password.php, (2) add_welcome_text.php, (3) admin_email.php, (4) add_templates.php, (5) admin_paypal_email.php, (6) approve_member.php, (7) delete_member.php, (8) index.php, (9) list_members.php, (10) membership_pricing.php, or (11) send_email.php in admin/; (12) config.php or (13) db_config.php in include/; or (14) add_category.php, (15) add_news.php, (16) change_catalog_template.php, (17) couple_milestone.php, (18) couple_profile.php, (19) delete_category.php, (20) index.php, (21) login.php, (22) logout.php, (23) register.php, (24) upload_photo.php, (25) user_catelog_password.php, (26) user_email.php, (27) user_extend.php, or (28) user_membership_password.php in user/.  NOTE: the include/common_function.php vector is already covered by another candidate from the same date.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0183">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1:sp1:enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1:sp10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1:sp10:enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1:sp2:enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1:sp3:enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1:sp4:enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1:sp5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1:sp5:enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1:sp6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1:sp6:enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1:sp7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1:sp7:enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1:sp8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1:sp8:enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1:sp9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:iplanet_web_server:4.1:sp9:enterprise"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1:sp1</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1:sp1:enterprise</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1:sp10</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1:sp10:enterprise</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1:sp2</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1:sp2:enterprise</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1:sp3</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1:sp3:enterprise</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1:sp4</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1:sp4:enterprise</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1:sp5</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1:sp5:enterprise</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1:sp6</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1:sp6:enterprise</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1:sp7</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1:sp7:enterprise</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1:sp8</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1:sp8:enterprise</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1:sp9</vuln:product>
      <vuln:product>cpe:/a:sun:iplanet_web_server:4.1:sp9:enterprise</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0183</vuln:cve-id>
    <vuln:published-datetime>2007-01-12T00:04:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:39:12.127-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21977" xml:lang="en">21977</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in /search in iPlanet Web Server 4.x allows remote attackers to inject arbitrary web script or HTML via the NS-max-records parameter.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0184">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:getahead:direct_web_remoting:0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:getahead:direct_web_remoting:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:getahead:direct_web_remoting:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:getahead:direct_web_remoting:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:getahead:direct_web_remoting:1.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:getahead:direct_web_remoting:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:getahead:direct_web_remoting:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:getahead:direct_web_remoting:1.1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:getahead:direct_web_remoting:0.7</vuln:product>
      <vuln:product>cpe:/a:getahead:direct_web_remoting:0.8</vuln:product>
      <vuln:product>cpe:/a:getahead:direct_web_remoting:0.9</vuln:product>
      <vuln:product>cpe:/a:getahead:direct_web_remoting:1.0</vuln:product>
      <vuln:product>cpe:/a:getahead:direct_web_remoting:1.1.0</vuln:product>
      <vuln:product>cpe:/a:getahead:direct_web_remoting:1.1.1</vuln:product>
      <vuln:product>cpe:/a:getahead:direct_web_remoting:1.1.2</vuln:product>
      <vuln:product>cpe:/a:getahead:direct_web_remoting:1.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0184</vuln:cve-id>
    <vuln:published-datetime>2007-01-12T00:04:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:02.280-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://getahead.ltd.uk/dwr/changelog" xml:lang="en">http://getahead.ltd.uk/dwr/changelog</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html" xml:lang="en">SUSE-SR:2009:004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21955" xml:lang="en">21955</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0095" xml:lang="en">ADV-2007-0095</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31377" xml:lang="en">dwr-include-exclude-security-bypass(31377)</vuln:reference>
    </vuln:references>
    <vuln:summary>Getahead Direct Web Remoting (DWR) before 1.1.4 allows attackers to obtain unauthorized access to public methods via a crafted request that bypasses the include/exclude checks.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0185">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:getahead:direct_web_remoting:0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:getahead:direct_web_remoting:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:getahead:direct_web_remoting:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:getahead:direct_web_remoting:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:getahead:direct_web_remoting:1.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:getahead:direct_web_remoting:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:getahead:direct_web_remoting:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:getahead:direct_web_remoting:1.1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:getahead:direct_web_remoting:0.7</vuln:product>
      <vuln:product>cpe:/a:getahead:direct_web_remoting:0.8</vuln:product>
      <vuln:product>cpe:/a:getahead:direct_web_remoting:0.9</vuln:product>
      <vuln:product>cpe:/a:getahead:direct_web_remoting:1.0</vuln:product>
      <vuln:product>cpe:/a:getahead:direct_web_remoting:1.1.0</vuln:product>
      <vuln:product>cpe:/a:getahead:direct_web_remoting:1.1.1</vuln:product>
      <vuln:product>cpe:/a:getahead:direct_web_remoting:1.1.2</vuln:product>
      <vuln:product>cpe:/a:getahead:direct_web_remoting:1.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0185</vuln:cve-id>
    <vuln:published-datetime>2007-01-12T00:04:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:02.327-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://getahead.ltd.uk/dwr/changelog" xml:lang="en">http://getahead.ltd.uk/dwr/changelog</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html" xml:lang="en">SUSE-SR:2009:004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21955" xml:lang="en">21955</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0095" xml:lang="en">ADV-2007-0095</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31382" xml:lang="en">dwr-servlet-engine-dos(31382)</vuln:reference>
    </vuln:references>
    <vuln:summary>Getahead Direct Web Remoting (DWR) before 1.1.4 allows attackers to cause a denial of service (memory exhaustion and servlet outage) via unknown vectors related to a large number of calls in a batch.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0186">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass_4100"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:f5:firepass_4100</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0186</vuln:cve-id>
    <vuln:published-datetime>2007-01-12T00:04:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:17:14.010-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-12T14:53:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051651.html" xml:lang="en">20070106 NNL-Labs &amp; MNIN - F5 FirePass Security Advisory</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.mnin.org/advisories/2007_firepass.pdf" xml:lang="en">http://www.mnin.org/advisories/2007_firepass.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21957" xml:lang="en">21957</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://tech.f5.com/home/solutions/sol6919.html" xml:lang="en">https://tech.f5.com/home/solutions/sol6919.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://tech.f5.com/home/solutions/sol6920.html" xml:lang="en">https://tech.f5.com/home/solutions/sol6920.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass SSL VPN allow remote attackers to inject arbitrary web script or HTML via (1) the xcho parameter to my.logon.php3; the (2) topblue, (3) midblue, (4) wtopblue, and certain other Custom color parameters in a per action to vdesk/admincon/index.php; the (5) h321, (6) h311, (7) h312, and certain other Front Door custom text color parameters in a per action to vdesk/admincon/index.php; the (8) ua parameter in a bro action to vdesk/admincon/index.php; the (9) app_param and (10) app_name parameters to webyfiers.php; (11) double eval functions; (12) JavaScript contained in an &lt;FP_DO_NOT_TOUCH> element; and (13) the vhost parameter to my.activation.php.  NOTE: it is possible that this candidate overlaps CVE-2006-3550.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0187">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.1"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.2"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.3"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.4"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.5"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.6"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.7"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.8"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.9"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.5"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.5.1"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.5.2"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:f5:firepass:5.4</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.1</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.2</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.3</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.4</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.5</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.6</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.7</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.8</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.9</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.5</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.5.1</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.5.2</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0187</vuln:cve-id>
    <vuln:published-datetime>2007-01-12T00:04:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:39:13.937-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0141.html" xml:lang="en">20070105 NNL-Labs &amp; MNIN - F5 FirePass Security Advisory</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051651.html" xml:lang="en">20070106 NNL-Labs &amp; MNIN - F5 FirePass Security Advisory</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.mnin.org/advisories/2007_firepass.pdf" xml:lang="en">http://www.mnin.org/advisories/2007_firepass.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21957" xml:lang="en">21957</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://tech.f5.com/home/solutions/sol6916.html" xml:lang="en">https://tech.f5.com/home/solutions/sol6916.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://tech.f5.com/home/solutions/sol6924.html" xml:lang="en">https://tech.f5.com/home/solutions/sol6924.html</vuln:reference>
    </vuln:references>
    <vuln:summary>F5 FirePass 5.4 through 5.5.2 and 6.0 allows remote attackers to access restricted URLs via (1) a trailing null byte, (2) multiple leading slashes, (3) Unicode encoding, (4) URL-encoded directory traversal or same-directory characters, or (5) upper case letters in the domain name.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0188">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.1"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.2"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.3"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.4"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.5"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.6"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.7"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.8"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.9"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.5"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.5.1"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.5.2"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:f5:firepass:5.4</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.1</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.2</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.3</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.4</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.5</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.6</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.7</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.8</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.9</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.5</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.5.1</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.5.2</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0188</vuln:cve-id>
    <vuln:published-datetime>2007-01-12T00:04:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:17:14.387-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-12T15:25:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051651.html" xml:lang="en">20070106 NNL-Labs &amp; MNIN - F5 FirePass Security Advisory</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.mnin.org/advisories/2007_firepass.pdf" xml:lang="en">http://www.mnin.org/advisories/2007_firepass.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21957" xml:lang="en">21957</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://tech.f5.com/home/solutions/sol6922.html" xml:lang="en">https://tech.f5.com/home/solutions/sol6922.html</vuln:reference>
    </vuln:references>
    <vuln:summary>F5 FirePass 5.4 through 5.5.1 does not properly enforce host access restrictions when a client uses a single integer (dword) representation of an IP address ("dotless IP address"), which allows remote authenticated users to connect to the FirePass administrator console and certain other network resources.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0189">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:geobb:georgian_bulletin_board"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:geobb:georgian_bulletin_board</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0189</vuln:cve-id>
    <vuln:published-datetime>2007-01-12T00:04:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:38.620-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2141" xml:lang="en">2141</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-January/001230.html" xml:lang="en">20070110 Dispute of GeoBB RFI</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456251/100/0/threaded" xml:lang="en">20070107 GeoBB Georgian Bulletin Board Remote File Include Vuln.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31335" xml:lang="en">geobb-index-file-include(31335)</vuln:reference>
    </vuln:references>
    <vuln:summary>** DISPUTED **  PHP remote file inclusion vulnerability in index.php in GeoBB Georgian Bulletin Board allows remote attackers to execute arbitrary PHP code via a URL in the action parameter.  NOTE: CVE disputes this issue, since GeoBB 1.0 sets $action to a whitelisted value.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0190">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:edit-x:ecommerce"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:edit-x:ecommerce</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0190</vuln:cve-id>
    <vuln:published-datetime>2007-01-12T00:04:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:38.977-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2139" xml:lang="en">2139</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456439/100/0/threaded" xml:lang="en">20070109 edit-x ecommerce (include_dir) Remote File include</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21974" xml:lang="en">21974</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0158" xml:lang="en">ADV-2007-0158</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31384" xml:lang="en">editx-editaddress-file-include(31384)</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in edit_address.php in edit-x ecommerce allows remote attackers to execute arbitrary PHP code via a URL in the include_dir parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0191">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mkportal:mkportal"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mkportal:mkportal</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0191</vuln:cve-id>
    <vuln:published-datetime>2007-01-12T00:04:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:39.370-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2138" xml:lang="en">2138</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456042/100/100/threaded" xml:lang="en">20070105 MkPortal Admin XSS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31304" xml:lang="en">mkportal-admin-xss(31304)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in admin.php in MKPortal allows remote attackers to inject arbitrary web script or HTML via two certain fields in a contents_new operation in the ad_contents section.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0192">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mkportal:mkportal"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mkportal:mkportal</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0192</vuln:cve-id>
    <vuln:published-datetime>2007-01-12T00:04:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:39.683-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2137" xml:lang="en">2137</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/455894/100/100/threaded" xml:lang="en">20070104 MkPortal "All Guests are Admin" Exploit</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site request forgery (CSRF) vulnerability in the save_main operation in the ad_perms section in admin.php in MKPortal allows remote attackers to modify privilege settings, as demonstrated using a getURL of admin.php within a .swf file contained in an IFRAME element, aka the "All Guests are Admin" attack.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0193">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:fon:la_fonera"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:fon:la_fonera</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0193</vuln:cve-id>
    <vuln:published-datetime>2007-01-12T00:04:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:39.900-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456128/100/0/threaded" xml:lang="en">20070106 FON Router allows anonymous web access</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456344/100/0/threaded" xml:lang="en">20070107 Re: FON Router allows anonymous web access</vuln:reference>
    </vuln:references>
    <vuln:summary>FON La Fonera routers do not properly limit DNS service access by unauthenticated clients, which allows remote attackers to tunnel traffic via DNS requests for hosts that should not be accessible before authentication.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0194">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mkportal:mkportal:1.1_rc1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mkportal:mkportal:1.1_rc1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0194</vuln:cve-id>
    <vuln:published-datetime>2007-01-12T00:04:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:40.137-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456257/100/0/threaded" xml:lang="en">20070108 MKPortal Full Path Disclosure</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31333" xml:lang="en">mkportal-admin-path-disclosure(31333)</vuln:reference>
    </vuln:references>
    <vuln:summary>admin.php in MKPortal M1.1 RC1 allows remote attackers to obtain sensitive information via a direct request with an MK_PATH=1 query string, which reveals the path in an error message.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0195">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.1"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.2"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.3"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.4"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.5"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.6"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.7"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.8"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.4.9"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.5"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:5.5.1"/>
        <cpe-lang:fact-ref name="cpe:/h:f5:firepass:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:f5:firepass:5.4</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.1</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.2</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.3</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.4</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.5</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.6</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.7</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.8</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.4.9</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.5</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:5.5.1</vuln:product>
      <vuln:product>cpe:/h:f5:firepass:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0195</vuln:cve-id>
    <vuln:published-datetime>2007-01-12T00:04:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:17:15.480-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-12T15:52:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051651.html" xml:lang="en">20070106 NNL-Labs &amp; MNIN - F5 FirePass Security Advisory</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.mnin.org/advisories/2007_firepass.pdf" xml:lang="en">http://www.mnin.org/advisories/2007_firepass.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21957" xml:lang="en">21957</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://tech.f5.com/home/solutions/sol6923.html" xml:lang="en">https://tech.f5.com/home/solutions/sol6923.html</vuln:reference>
    </vuln:references>
    <vuln:summary>my.activation.php3 in F5 FirePass 5.4 through 5.5.1 and 6.0 displays different error messages for failed login attempts with a valid username than for those with an invalid username, which allows remote attackers to confirm the validity of an LDAP account.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0196">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:motionborg:motionborg_web_real_estate:2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:motionborg:motionborg_web_real_estate:2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0196</vuln:cve-id>
    <vuln:published-datetime>2007-01-11T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:57.207-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21963" xml:lang="en">21963</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0143" xml:lang="en">ADV-2007-0143</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31360" xml:lang="en">motionborg-admincheckuser-sql-injection(31360)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3105" xml:lang="en">3105</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in admin_check_user.asp in Motionborg Web Real Estate 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the username field (txtUserName parameter) and possibly other parameters.  NOTE: some details were obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0197">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0197</vuln:cve-id>
    <vuln:published-datetime>2007-01-11T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:40.417-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305102" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305102</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Feb/msg00000.html" xml:lang="en">APPLE-SA-2007-02-15</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-09-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-09-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.digitalmunition.com/DMA%5B2007-0109a%5D.txt" xml:lang="en">http://www.digitalmunition.com/DMA%5B2007-0109a%5D.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/240880" xml:lang="en">VU#240880</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456578/100/0/threaded" xml:lang="en">20070111 DMA[2007-0107a] OmniWeb Javascript Alert Format String Vulnerabiity and DMA[2007-0109a] Apple Finder Disk Image Volume Label Overflow / DoS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21980" xml:lang="en">21980</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017662" xml:lang="en">1017662</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-047A.html" xml:lang="en">TA07-047A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0140" xml:lang="en">ADV-2007-0140</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31410" xml:lang="en">macos-finder-dos(31410)</vuln:reference>
    </vuln:references>
    <vuln:summary>Finder 10.4.6 on Apple Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a long volume name in a DMG disk image, which results in memory corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0198">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cisco:ip_contact_center_enterprise:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:ip_contact_center_enterprise:7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:ip_contact_center_hosted:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:ip_contact_center_hosted:7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_contact_center_enterprise:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_contact_center_enterprise:7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_contact_center_hosted:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:unified_contact_center_hosted:7.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cisco:ip_contact_center_enterprise:5.0</vuln:product>
      <vuln:product>cpe:/a:cisco:ip_contact_center_enterprise:7.1</vuln:product>
      <vuln:product>cpe:/a:cisco:ip_contact_center_hosted:5.0</vuln:product>
      <vuln:product>cpe:/a:cisco:ip_contact_center_hosted:7.1</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_contact_center_enterprise:5.0</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_contact_center_enterprise:7.1</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_contact_center_hosted:5.0</vuln:product>
      <vuln:product>cpe:/a:cisco:unified_contact_center_hosted:7.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0198</vuln:cve-id>
    <vuln:published-datetime>2007-01-11T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:48:59.893-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017499" xml:lang="en">1017499</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20070110-jtapi.shtml" xml:lang="en">20070110 Cisco Unified Contact Center and IP Contact Center JTapi Gateway Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21988" xml:lang="en">21988</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0138" xml:lang="en">ADV-2007-0138</vuln:reference>
    </vuln:references>
    <vuln:summary>The JTapi Gateway process in Cisco Unified Contact Center Enterprise, Unified Contact Center Hosted, IP Contact Center Enterprise, and Cisco IP Contact Center Hosted 5.0 through 7.1 allows remote attackers to cause a denial of service (repeated process restart) via a certain TCP session on the JTapi server port.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0199">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.0"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:cisco:ios:11.0</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0199</vuln:cve-id>
    <vuln:published-datetime>2007-01-11T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:34.610-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5714" name="oval:org.mitre.oval:def:5714"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017498" xml:lang="en">1017498</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20070110-dlsw.shtml" xml:lang="en">20070110 DLSw Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21990" xml:lang="en">21990</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0139" xml:lang="en">ADV-2007-0139</vuln:reference>
    </vuln:references>
    <vuln:summary>The Data-link Switching (DLSw) feature in Cisco IOS 11.0 through 12.4 allows remote attackers to cause a denial of service (device reload) via "an invalid value in a DLSw message... during the capabilities exchange."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0200">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:geoffrey_golliher:axiom_photo_news_gallery:0.8.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:geoffrey_golliher:axiom_photo_news_gallery:0.8.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0200</vuln:cve-id>
    <vuln:published-datetime>2007-01-11T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:57.253-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-January/001233.html" xml:lang="en">20070110 source verify - Axiom RFI</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21972" xml:lang="en">21972</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0107" xml:lang="en">ADV-2007-0107</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31372" xml:lang="en">axiom-template-file-include(31372)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3108" xml:lang="en">3108</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in template.php in Geoffrey Golliher Axiom Photo/News Gallery (axiompng) 0.8.6 allows remote attackers to execute arbitrary PHP code via a URL in the baseAxiomPath parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0201">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:tis:internet_firewall_toolkit:2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:tis:internet_firewall_toolkit:2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0201</vuln:cve-id>
    <vuln:published-datetime>2007-01-11T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:02.767-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017481" xml:lang="en">1017481</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.ranum.com/security/computer_security/editorials/codetools/" xml:lang="en">http://www.ranum.com/security/computer_security/editorials/codetools/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21960" xml:lang="en">21960</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31363" xml:lang="en">tisfwtk-ftpgw-bo(31363)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the cmd_usr function in ftp-gw in TIS Internet Firewall Toolkit (FWTK) allows remote attackers to execute arbitrary code via a long destination hostname (dest).</vuln:summary>
  </entry>
  <entry id="CVE-2007-0202">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:alexphpteam:alex_guestbook:3.12"/>
        <cpe-lang:fact-ref name="cpe:/a:alexphpteam:alex_guestbook:3.13"/>
        <cpe-lang:fact-ref name="cpe:/a:alexphpteam:alex_guestbook:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:alexphpteam:alex_guestbook:4.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:alexphpteam:alex_guestbook:3.12</vuln:product>
      <vuln:product>cpe:/a:alexphpteam:alex_guestbook:3.13</vuln:product>
      <vuln:product>cpe:/a:alexphpteam:alex_guestbook:4.0.1</vuln:product>
      <vuln:product>cpe:/a:alexphpteam:alex_guestbook:4.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0202</vuln:cve-id>
    <vuln:published-datetime>2007-01-11T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:41.277-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://acid-root.new.fr/poc/20070107.txt" xml:lang="en">http://acid-root.new.fr/poc/20070107.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2135" xml:lang="en">2135</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456218/100/0/threaded" xml:lang="en">20070107 @lex Guestbook &lt;= 4.0.2 Remote Command Execution Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21926" xml:lang="en">21926</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0137" xml:lang="en">ADV-2007-0137</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31393" xml:lang="en">@lexguestbook-index-sql-injection(31393)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3103" xml:lang="en">3103</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in index.php in @lex Guestbook 4.0.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the lang parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0203">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.9.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.9.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0203</vuln:cve-id>
    <vuln:published-datetime>2007-01-11T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:00.393-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:199" xml:lang="en">MDKSA-2007:199</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.phpmyadmin.net/home_page/downloads.php?relnotes=0" xml:lang="en">http://www.phpmyadmin.net/home_page/downloads.php?relnotes=0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21987" xml:lang="en">21987</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0125" xml:lang="en">ADV-2007-0125</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple unspecified vulnerabilities in phpMyAdmin before 2.9.2-rc1 have unknown impact and attack vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0204">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.9.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.9.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0204</vuln:cve-id>
    <vuln:published-datetime>2007-01-11T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:02.877-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:199" xml:lang="en">MDKSA-2007:199</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.phpmyadmin.net/home_page/downloads.php?relnotes=0" xml:lang="en">http://www.phpmyadmin.net/home_page/downloads.php?relnotes=0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21987" xml:lang="en">21987</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0125" xml:lang="en">ADV-2007-0125</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31387" xml:lang="en">phpmyadmin-unspecified-xss(31387)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.9.2-rc1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: some of these details are obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0205">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:alexphpteam:alex_guestbook:3.12"/>
        <cpe-lang:fact-ref name="cpe:/a:alexphpteam:alex_guestbook:3.13"/>
        <cpe-lang:fact-ref name="cpe:/a:alexphpteam:alex_guestbook:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:alexphpteam:alex_guestbook:4.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:alexphpteam:alex_guestbook:3.12</vuln:product>
      <vuln:product>cpe:/a:alexphpteam:alex_guestbook:3.13</vuln:product>
      <vuln:product>cpe:/a:alexphpteam:alex_guestbook:4.0.1</vuln:product>
      <vuln:product>cpe:/a:alexphpteam:alex_guestbook:4.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0205</vuln:cve-id>
    <vuln:published-datetime>2007-01-11T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:41.933-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://acid-root.new.fr/poc/20070107.txt" xml:lang="en">http://acid-root.new.fr/poc/20070107.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2135" xml:lang="en">2135</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456218/100/0/threaded" xml:lang="en">20070107 @lex Guestbook &lt;= 4.0.2 Remote Command Execution Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21926" xml:lang="en">21926</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31397" xml:lang="en">@lexguestbook-livreinclude-file-include(31397)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3103" xml:lang="en">3103</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in admin/skins.php for @lex Guestbook 4.0.2 and earlier allows remote attackers to create files in arbitrary directories via ".." sequences in the (1) aj_skin and (2) skin_edit parameters.  NOTE: this can be leveraged for file inclusion by creating a skin file in the lang directory, then referencing that file via the lang parameter to index.php, which passes a sanity check in livre_include.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0206">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.2::hp_ux_10.x"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.2::hp_ux_11.x"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.2::nt_4.x_windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.2::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.4::hp_ux_11.x"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.4::nt_4.x_windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.4::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.41"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.41::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:7.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:7.0.1::hp_ux_11.x"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:7.0.1::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:7.0.1::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:7.0.1::windows_2000_xp"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:7.50"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:7.50::hp_ux_11.x"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:7.50::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:7.50::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:7.50::windows_2000_xp"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.2</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.2::hp_ux_10.x</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.2::hp_ux_11.x</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.2::nt_4.x_windows_2000</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.2::solaris</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.4</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.4::hp_ux_11.x</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.4::nt_4.x_windows_2000</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.4::solaris</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.41</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.41::solaris</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:7.0.1</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:7.0.1::hp_ux_11.x</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:7.0.1::linux</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:7.0.1::solaris</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:7.0.1::windows_2000_xp</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:7.50</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:7.50::hp_ux_11.x</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:7.50::linux</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:7.50::solaris</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:7.50::windows_2000_xp</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0206</vuln:cve-id>
    <vuln:published-datetime>2007-01-11T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:42.557-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2140" xml:lang="en">2140</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017503" xml:lang="en">1017503</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456615/100/0/threaded" xml:lang="en">SSRT061174</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22009" xml:lang="en">22009</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0153" xml:lang="en">ADV-2007-0153</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 6.20, 6.4x, 7.01, and 7.50 allows remote attackers to read arbitrary files via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0207">
    <vuln:cve-id>CVE-2007-0207</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:05.527-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:05.527-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2007. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0208">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2004::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word_viewer:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2004"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2005"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2006"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2004::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:word_viewer:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2004</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2005</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2006</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0208</vuln:cve-id>
    <vuln:published-datetime>2007-02-13T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:42:28.767-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A700" name="oval:org.mitre.oval:def:700"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22477" xml:lang="en">22477</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017639" xml:lang="en">1017639</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" xml:lang="en">TA07-044A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0583" xml:lang="en">ADV-2007-0583</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-014" xml:lang="en">MS07-014</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac does not correctly check the properties of certain documents and warn the user of macro content, which allows user-assisted remote attackers to execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0209">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2004::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2004"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2005"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2006"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2004::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2004</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2005</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2006</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0209</vuln:cve-id>
    <vuln:published-datetime>2007-02-13T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:42:29.390-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A187" name="oval:org.mitre.oval:def:187"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22482" xml:lang="en">22482</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017639" xml:lang="en">1017639</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" xml:lang="en">TA07-044A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0583" xml:lang="en">ADV-2007-0583</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-014" xml:lang="en">MS07-014</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a Word file with a malformed drawing object, which leads to memory corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0210">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:tablet_pc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:tablet_pc</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0210</vuln:cve-id>
    <vuln:published-datetime>2007-02-13T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:42:30.047-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A186" name="oval:org.mitre.oval:def:186"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22499" xml:lang="en">22499</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017634" xml:lang="en">1017634</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" xml:lang="en">TA07-044A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0576" xml:lang="en">ADV-2007-0576</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-007" xml:lang="en">MS07-007</vuln:reference>
    </vuln:references>
    <vuln:summary>The Window Image Acquisition (WIA) Service in Microsoft Windows XP SP2 allows local users to gain privileges via unspecified vectors involving an "unchecked buffer," probably a buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0211">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:tablet_pc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:tablet_pc</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0211</vuln:cve-id>
    <vuln:published-datetime>2007-02-13T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:42:30.750-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A224" name="oval:org.mitre.oval:def:224"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/240796" xml:lang="en">VU#240796</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22481" xml:lang="en">22481</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017633" xml:lang="en">1017633</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" xml:lang="en">TA07-044A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0575" xml:lang="en">ADV-2007-0575</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-006" xml:lang="en">MS07-006</vuln:reference>
    </vuln:references>
    <vuln:summary>The hardware detection functionality in the Windows Shell in Microsoft Windows XP SP2 and Professional, and Server 2003 SP1 allows local users to gain privileges via an unvalidated parameter to a function related to the "detection and registration of new hardware."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0212">
    <vuln:cve-id>CVE-2007-0212</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:05.557-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:05.557-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2007. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0213">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2003:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2007"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:exchange_server:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:2003:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:2007</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0213</vuln:cve-id>
    <vuln:published-datetime>2007-05-08T19:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:42.993-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1890" name="oval:org.mitre.oval:def:1890"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://packetstormsecurity.com/files/153533/Microsoft-Exchange-2003-base64-MIME-Remote-Code-Execution.html" xml:lang="en">http://packetstormsecurity.com/files/153533/Microsoft-Exchange-2003-base64-MIME-Remote-Code-Execution.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/343145" xml:lang="en">VU#343145</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/468871/100/200/threaded" xml:lang="en">HPSBST02214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23809" xml:lang="en">23809</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018015" xml:lang="en">1018015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" xml:lang="en">TA07-128A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1711" xml:lang="en">ADV-2007-1711</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-026" xml:lang="en">MS07-026</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33889" xml:lang="en">exchange-mime-base64-code-execution(33889)</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 does not properly decode certain MIME encoded e-mails, which allows remote attackers to execute arbitrary code via a crafted base64-encoded MIME e-mail message.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0214">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1::itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::64-bit"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp1::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::64-bit</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0214</vuln:cve-id>
    <vuln:published-datetime>2007-02-13T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:42:32.593-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A125" name="oval:org.mitre.oval:def:125"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/563756" xml:lang="en">VU#563756</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22478" xml:lang="en">22478</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017635" xml:lang="en">1017635</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" xml:lang="en">TA07-044A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0577" xml:lang="en">ADV-2007-0577</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-008" xml:lang="en">MS07-008</vuln:reference>
    </vuln:references>
    <vuln:summary>The HTML Help ActiveX control (Hhctrl.ocx) in Microsoft Windows 2000 SP3, XP SP2 and Professional, 2003 SP1 allows remote attackers to execute arbitrary code via unspecified functions, related to uninitialized parameters.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0215">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2007"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel_viewer:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2004::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2007"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:excel:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2007</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel_viewer:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2004::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2007</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0215</vuln:cve-id>
    <vuln:published-datetime>2007-05-08T18:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:43.870-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1971" name="oval:org.mitre.oval:def:1971"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/467988/100/0/threaded" xml:lang="en">20070508 ZDI-07-026: Microsoft Excel BIFF File Format Named Graph Record Parsing Stack Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/468871/100/200/threaded" xml:lang="en">HPSBST02214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23760" xml:lang="en">23760</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018012" xml:lang="en">1018012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" xml:lang="en">TA07-128A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1708" xml:lang="en">ADV-2007-1708</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-07-026.html" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-07-026.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-023" xml:lang="en">MS07-023</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33913" xml:lang="en">excel-biff-file-bo(33913)</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, and 2003 Viewer allows user-assisted remote attackers to execute arbitrary code via a .XLS BIFF file with a malformed Named Graph record, which results in memory corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0216">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2005"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:8.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2005</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0216</vuln:cve-id>
    <vuln:published-datetime>2008-02-12T18:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:42:34.610-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5309" name="oval:org.mitre.oval:def:5309"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=659" xml:lang="en">20080208 Microsoft Office Works Converter Heap Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" xml:lang="en">HPSBST02314</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27657" xml:lang="en">27657</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019386" xml:lang="en">1019386</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-043C.html" xml:lang="en">TA08-043C</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0513/references" xml:lang="en">ADV-2008-0513</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-011" xml:lang="en">MS08-011</vuln:reference>
    </vuln:references>
    <vuln:summary>wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section length headers, aka "Microsoft Works File Converter Input Validation Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0217">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.01:sp4"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:gold"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:gold::itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:gold::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1::itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.01:sp4</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0217</vuln:cve-id>
    <vuln:published-datetime>2007-02-13T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:44.900-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1141" name="oval:org.mitre.oval:def:1141"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=473" xml:lang="en">20070213 Microsoft 'wininet.dll' FTP Reply Null Termination Heap Corruption Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/613564" xml:lang="en">VU#613564</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/462303/100/0/threaded" xml:lang="en">20070309 MS07-016 FTP Response DOS PoC</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22489" xml:lang="en">22489</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017642" xml:lang="en">1017642</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" xml:lang="en">TA07-044A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0584" xml:lang="en">ADV-2007-0584</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-016" xml:lang="en">MS07-016</vuln:reference>
    </vuln:references>
    <vuln:summary>The wininet.dll FTP client code in Microsoft Internet Explorer 5.01 and 6 might allow remote attackers to execute arbitrary code via an FTP server response of a specific length that causes a terminating null byte to be written outside of a buffer, which causes heap corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0218">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.01:sp4"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6:sp1"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::professional_x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server::sp2:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1::itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp2::itanium"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::gold"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::gold:x64"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.01:sp4</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:7.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0218</vuln:cve-id>
    <vuln:published-datetime>2007-06-12T15:30:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:45.917-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1084" name="oval:org.mitre.oval:def:1084"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=542" xml:lang="en">20070612 Microsoft License Manager and urlmon.dll COM Object Interaction Invalid Memory Access Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1018235" xml:lang="en">1018235</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/471947/100/0/threaded" xml:lang="en">SSRT071438</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/24372" xml:lang="en">24372</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-163A.html" xml:lang="en">TA07-163A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2153" xml:lang="en">ADV-2007-2153</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-033" xml:lang="en">MS07-033</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32106" xml:lang="en">webbrowser-object-code-execution(32106)</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Internet Explorer 5.01 and 6 allows remote attackers to execute arbitrary code by instantiating certain COM objects from Urlmon.dll, which triggers memory corruption during a call to the IObjectSafety function.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0219">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.01:sp4"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:gold"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:gold::itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:gold::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1::itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:gold::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1::itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional_x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.01:sp4</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:7.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0219</vuln:cve-id>
    <vuln:published-datetime>2007-02-13T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:42:38.203-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A257" name="oval:org.mitre.oval:def:257"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/771788" xml:lang="en">VU#771788</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22504" xml:lang="en">22504</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017643" xml:lang="en">1017643</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" xml:lang="en">TA07-044A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0584" xml:lang="en">ADV-2007-0584</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-016" xml:lang="en">MS07-016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32427" xml:lang="en">ie-com-activex-code-execution(32427)</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Internet Explorer 5.01, 6, and 7 uses certain COM objects from (1) Msb1fren.dll, (2) Htmlmm.ocx, and (3) Blnmgrps.dll as ActiveX controls, which allows remote attackers to execute arbitrary code via unspecified vectors, a different issue than CVE-2006-4697.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0220">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2003:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2003:sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:exchange_server:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:2003:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:2003:sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0220</vuln:cve-id>
    <vuln:published-datetime>2007-05-08T19:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:47.137-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1371" name="oval:org.mitre.oval:def:1371"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/124113" xml:lang="en">VU#124113</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/468871/100/200/threaded" xml:lang="en">HPSBST02214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23806" xml:lang="en">23806</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018015" xml:lang="en">1018015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" xml:lang="en">TA07-128A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1711" xml:lang="en">ADV-2007-1711</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-026" xml:lang="en">MS07-026</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33887" xml:lang="en">exchange-utf-xss(33887)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2000 SP3, and 2003 SP1 and SP2 allows remote attackers to execute arbitrary scripts, spoof content, or obtain sensitive information via certain UTF-encoded, script-based e-mail attachments, involving an "incorrectly handled UTF character set label".</vuln:summary>
  </entry>
  <entry id="CVE-2007-0221">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:2000:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:exchange_server:2000:sp3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0221</vuln:cve-id>
    <vuln:published-datetime>2007-05-08T19:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:47.947-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2054" name="oval:org.mitre.oval:def:2054"/>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=526" xml:lang="en">20070508 Microsoft Exchange Server 2000 IMAP Literal Processing DoS Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/468871/100/200/threaded" xml:lang="en">HPSBST02214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23810" xml:lang="en">23810</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018015" xml:lang="en">1018015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" xml:lang="en">TA07-128A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1711" xml:lang="en">ADV-2007-1711</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-026" xml:lang="en">MS07-026</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33890" xml:lang="en">exchange-imap-command-dos(33890)</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in the IMAP (IMAP4) support in Microsoft Exchange Server 2000 SP3 allows remote attackers to cause a denial of service (service hang) via crafted literals in an IMAP command, aka the "IMAP Literal Processing Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0222">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:application_server:10.1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:application_server:10.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0222</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:48.823-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017522" xml:lang="en">1017522</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457105/100/0/threaded" xml:lang="en">20070115 SYMSA-2007-001: Oracle Application Server 10g - Directory Traversal</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458657/100/0/threaded" xml:lang="en">20070131 Oracle 10g R2 Enterprise Manager Directory Traversal</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22027" xml:lang="en">22027</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22083" xml:lang="en">22083</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in the EmChartBean server side component for Oracle Application Server 10g allows remote attackers to read arbitrary files via unknown vectors, probably "\.." sequences in the beanId parameter.  NOTE: this is likely a duplicate of another CVE that Oracle addressed in CPU Jan 2007, but due to lack of details by Oracle, it is unclear which BugID this issue is associated with, so the other CVE cannot be determined.  Possibilities include EM02 (CVE-2007-0292) or EM05 (CVE-2007-0293).</vuln:summary>
  </entry>
  <entry id="CVE-2007-0223">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nicola_asuni:all_in_one_control_panel:1.3.000"/>
        <cpe-lang:fact-ref name="cpe:/a:nicola_asuni:all_in_one_control_panel:1.3.001"/>
        <cpe-lang:fact-ref name="cpe:/a:nicola_asuni:all_in_one_control_panel:1.3.002"/>
        <cpe-lang:fact-ref name="cpe:/a:nicola_asuni:all_in_one_control_panel:1.3.003"/>
        <cpe-lang:fact-ref name="cpe:/a:nicola_asuni:all_in_one_control_panel:1.3.004"/>
        <cpe-lang:fact-ref name="cpe:/a:nicola_asuni:all_in_one_control_panel:1.3.005"/>
        <cpe-lang:fact-ref name="cpe:/a:nicola_asuni:all_in_one_control_panel:1.3.006"/>
        <cpe-lang:fact-ref name="cpe:/a:nicola_asuni:all_in_one_control_panel:1.3.007"/>
        <cpe-lang:fact-ref name="cpe:/a:nicola_asuni:all_in_one_control_panel:1.3.008"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nicola_asuni:all_in_one_control_panel:1.3.000</vuln:product>
      <vuln:product>cpe:/a:nicola_asuni:all_in_one_control_panel:1.3.001</vuln:product>
      <vuln:product>cpe:/a:nicola_asuni:all_in_one_control_panel:1.3.002</vuln:product>
      <vuln:product>cpe:/a:nicola_asuni:all_in_one_control_panel:1.3.003</vuln:product>
      <vuln:product>cpe:/a:nicola_asuni:all_in_one_control_panel:1.3.004</vuln:product>
      <vuln:product>cpe:/a:nicola_asuni:all_in_one_control_panel:1.3.005</vuln:product>
      <vuln:product>cpe:/a:nicola_asuni:all_in_one_control_panel:1.3.006</vuln:product>
      <vuln:product>cpe:/a:nicola_asuni:all_in_one_control_panel:1.3.007</vuln:product>
      <vuln:product>cpe:/a:nicola_asuni:all_in_one_control_panel:1.3.008</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0223</vuln:cve-id>
    <vuln:published-datetime>2007-01-12T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:03.407-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=477845" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=477845</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22019" xml:lang="en">22019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31591" xml:lang="en">aiocp-cpfunctionsdownloads-sql-injection(31591)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in shared/code/cp_functions_downloads.php in Nicola Asuni All In One Control Panel (AIOCP) before 1.3.009 allows remote attackers to execute arbitrary SQL commands via the download_category parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0224">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:virtual_programming:vp-asp:6.09"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:virtual_programming:vp-asp:6.09</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0224</vuln:cve-id>
    <vuln:published-datetime>2007-01-12T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:57.613-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31447" xml:lang="en">vpasp-shopgift-sql-injection(31447)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3115" xml:lang="en">3115</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in shopgiftregsearch.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote attackers to execute arbitrary SQL commands via the LoginLastname parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0225">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:virtual_programming:vp-asp:6.09"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:virtual_programming:vp-asp:6.09</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0225</vuln:cve-id>
    <vuln:published-datetime>2007-01-12T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:57.707-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31449" xml:lang="en">vpasp-shopcustadmin-xss(31449)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3115" xml:lang="en">3115</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in shopcustadmin.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0226">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:uniforum:uniforum:4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:uniforum:uniforum:4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0226</vuln:cve-id>
    <vuln:published-datetime>2007-01-12T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:49.290-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458060/100/0/threaded" xml:lang="en">20070125 uniForum &lt;= v4 (wbsearch.aspx) Remote SQL Injection Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21966" xml:lang="en">21966</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31362" xml:lang="en">uniforum-wbsearch-sql-injection(31362)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3106" xml:lang="en">3106</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in wbsearch.aspx in uniForum 4 and earlier allows remote attackers to execute arbitrary SQL commands via the "by User" field (aka the TXbyuser parameter).</vuln:summary>
  </entry>
  <entry id="CVE-2007-0227">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:slocate:slocate:3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:slocate:slocate:3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0227</vuln:cve-id>
    <vuln:published-datetime>2007-01-12T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:49.777-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456489/100/0/threaded" xml:lang="en">20070110 slocate leaks filenames of protected directories</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456530/100/0/threaded" xml:lang="en">20070110 Re: slocate leaks filenames of protected directories</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456593/100/0/threaded" xml:lang="en">20070111 Re: slocate leaks filenames of protected directories</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456739/100/0/threaded" xml:lang="en">20070112 Re: slocate leaks filenames of protected directories</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/464220/30/7320/threaded" xml:lang="en">20070329 FLEA-2007-0005-1: slocate</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21989" xml:lang="en">21989</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-425-1" xml:lang="en">USN-425-1</vuln:reference>
    </vuln:references>
    <vuln:summary>slocate 3.1 does not properly manage database entries that specify names of files in protected directories, which allows local users to obtain the names of private files.  NOTE: another researcher reports that the issue is not present in slocate 2.7.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0228">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:eiqnetworks:enterprise_security_analyzer:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:eiqnetworks:enterprise_security_analyzer:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:eiqnetworks:enterprise_security_analyzer:2.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:eiqnetworks:enterprise_security_analyzer:2.0</vuln:product>
      <vuln:product>cpe:/a:eiqnetworks:enterprise_security_analyzer:2.1</vuln:product>
      <vuln:product>cpe:/a:eiqnetworks:enterprise_security_analyzer:2.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0228</vuln:cve-id>
    <vuln:published-datetime>2007-01-12T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:03.657-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0209.html" xml:lang="en">20070110 EIQ Networks Network Security Analyzer DoS Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21994" xml:lang="en">21994</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0147" xml:lang="en">ADV-2007-0147</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31428" xml:lang="en">eiq-datacollector-dos(31428)</vuln:reference>
    </vuln:references>
    <vuln:summary>The DataCollector service in EIQ Networks Network Security Analyzer allows remote attackers to cause a denial of service (service crash) via a (1) &amp;CONNECTSERVER&amp; (2) &amp;ADDENTRY&amp; (3) &amp;FIN&amp; (4) &amp;START&amp; (5) &amp;LOGPATH&amp; (6) &amp;FWADELTA&amp; (7) &amp;FWALOG&amp; (8) &amp;SETSYNCHRONOUS&amp; (9) &amp;SETPRGFILE&amp;, or (10) &amp;SETREPLYPORT&amp; string to TCP port 10618, which triggers a NULL pointer dereference.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0229">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:6.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.8</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0229</vuln:cve-id>
    <vuln:published-datetime>2007-01-12T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:03.717-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://applefun.blogspot.com/2007/01/moab-10-01-2007-apple-dmg-ufs.html" xml:lang="en">http://applefun.blogspot.com/2007/01/moab-10-01-2007-apple-dmg-ufs.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305214" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" xml:lang="en">APPLE-SA-2007-03-13</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.freebsd.org/pipermail/freebsd-security/2007-January/004218.html" xml:lang="en">[freebsd-security] 20070114 MOAB advisories</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-10-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-10-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21993" xml:lang="en">21993</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017751" xml:lang="en">1017751</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" xml:lang="en">TA07-072A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0141" xml:lang="en">ADV-2007-0141</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0930" xml:lang="en">ADV-2007-0930</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31409" xml:lang="en">macos-ffsmountfs-bo(31409)</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in the ffs_mountfs function in Mac OS X 10.4.8 and FreeBSD 6.1 allows local users to cause a denial of service (panic) and possibly gain privileges via a crafted DMG image that causes "allocation of a negative size buffer" leading to a heap-based buffer overflow, a related issue to CVE-2006-5679.  NOTE: a third party states that this issue does not cross privilege boundaries in FreeBSD because only root may mount a filesystem.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0230">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cs-cart:cs-cart:1.3.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cs-cart:cs-cart:1.3.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0230</vuln:cve-id>
    <vuln:published-datetime>2007-01-12T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:52.900-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-January/001223.html" xml:lang="en">20070110 [bogus] [ahmed_labib_hilmy at yahoo.com: CS-Cart 1.3.3 (install.php) Remote File Include Vulnerability] (fwd)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456527/100/0/threaded" xml:lang="en">20070109 CS-Cart 1.3.3 (install.php) Remote File Include Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31408" xml:lang="en">cscart-install-file-include(31408)</vuln:reference>
    </vuln:references>
    <vuln:summary>** DISPUTED ** PHP remote file inclusion vulnerability in install.php in CS-Cart 1.3.3 allows remote attackers to execute arbitrary PHP code via a URL in the install_dir parameter.  NOTE: CVE and third parties dispute this vulnerability because install_dir is defined before use.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0231">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:six_apart:movable_type:3.33"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:six_apart:movable_type:3.33</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0231</vuln:cve-id>
    <vuln:published-datetime>2007-01-12T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:02.797-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://golem.ph.utexas.edu/~distler/blog/archives/001102.html" xml:lang="en">http://golem.ph.utexas.edu/~distler/blog/archives/001102.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0142" xml:lang="en">ADV-2007-0142</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zackvision.com/weblog/2007/01/movabletype-security-bug.html" xml:lang="en">http://www.zackvision.com/weblog/2007/01/movabletype-security-bug.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Movable Type (MT) 3.33, when nofollow is disabled and unmoderated comments are enabled, allows remote attackers to inject arbitrary web script or HTML via the Comments field.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0232">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:jshop_e-commerce:jshop_server:1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:jshop_e-commerce:jshop_server:1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0232</vuln:cve-id>
    <vuln:published-datetime>2007-01-12T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:53.197-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2146" xml:lang="en">2146</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456591/100/0/threaded" xml:lang="en">20070110 Jshop Server 1.3</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21995" xml:lang="en">21995</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31425" xml:lang="en">jshop-fieldvalidation-file-include(31425)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3113" xml:lang="en">3113</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in routines/fieldValidation.php in Jshop Server 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the jssShopFileSystem parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0233">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:0.6.2:beta_2"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:0.6.2.1:beta_2"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:0.71"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:1.5.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:1.5.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wordpress:wordpress:0.6.2:beta_2</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:0.6.2.1:beta_2</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:0.7</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:0.71</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:1.2</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:1.2.1</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:1.2.2</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:1.5</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:1.5.1</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:1.5.1.2</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:1.5.1.3</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:1.5.2</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.1</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.2</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.3</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.4</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.5</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0233</vuln:cve-id>
    <vuln:published-datetime>2007-01-12T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:57.877-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21983" xml:lang="en">21983</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31385" xml:lang="en">wordpress-tbid-sql-injection(31385)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3109" xml:lang="en">3109</vuln:reference>
    </vuln:references>
    <vuln:summary>wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary SQL commands via the tb_id parameter.  NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in WordPress.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0234">
    <vuln:cve-id>CVE-2007-0234</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:48:43.493-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2007-0243.  Reason: This candidate is a duplicate of CVE-2007-0243.  Notes: All CVE users should reference CVE-2007-0243 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0235">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:libgtop:libgtop:2.14.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:libgtop:libgtop:2.14.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0235</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:35.767-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.7</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10720" name="oval:org.mitre.oval:def:10720"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugzilla.gnome.org/show_bug.cgi?id=396477" xml:lang="en">http://bugzilla.gnome.org/show_bug.cgi?id=396477</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://ftp.gnome.org/pub/gnome/sources/libgtop/2.14/libgtop-2.14.6.news" xml:lang="en">http://ftp.gnome.org/pub/gnome/sources/libgtop/2.14/libgtop-2.14.6.news</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200701-17.xml" xml:lang="en">GLSA-200701-17</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1255" xml:lang="en">DSA-1255</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:023" xml:lang="en">MDKSA-2007:023</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0765.html" xml:lang="en">RHSA-2007:0765</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22054" xml:lang="en">22054</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018526" xml:lang="en">1018526</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-407-1" xml:lang="en">USN-407-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0185" xml:lang="en">ADV-2007-0185</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0187" xml:lang="en">ADV-2007-0187</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31522" xml:lang="en">libgtop2-glibtopbo(31522)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-972" xml:lang="en">https://issues.rpath.com/browse/RPL-972</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://launchpad.net/bugs/79206" xml:lang="en">https://launchpad.net/bugs/79206</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in the glibtop_get_proc_map_s function in libgtop before 2.14.6 (libgtop2) allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a process with a long filename that is mapped in its address space, which triggers the overflow in gnome-system-monitor.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0236">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0236</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:35.830-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305214" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" xml:lang="en">APPLE-SA-2007-03-13</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-14-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-14-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017513" xml:lang="en">1017513</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22041" xml:lang="en">22041</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017751" xml:lang="en">1017751</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" xml:lang="en">TA07-072A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0191" xml:lang="en">ADV-2007-0191</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0930" xml:lang="en">ADV-2007-0930</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3130" xml:lang="en">3130</vuln:reference>
    </vuln:references>
    <vuln:summary>Double free vulnerability in the _ATPsndrsp function in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to cause a denial of service (kernel panic) and possibly execute arbitrary code via a crafted AppleTalk request that triggers a heap-based buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0237">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:lookup:lookup"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:lookup:lookup</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0237</vuln:cve-id>
    <vuln:published-datetime>2007-03-19T15:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:04.030-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.gentoo.org/show_bug.cgi?id=197306" xml:lang="en">http://bugs.gentoo.org/show_bug.cgi?id=197306</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200712-07.xml" xml:lang="en">GLSA-200712-07</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1269" xml:lang="en">DSA-1269</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23026" xml:lang="en">23026</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017792" xml:lang="en">1017792</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33052" xml:lang="en">lookup-ndebbinary-symlink(33052)</vuln:reference>
    </vuln:references>
    <vuln:summary>The ndeb-binary feature in Lookup (lookup-el) allows local users to overwrite arbitrary files via a symlink attack on temporary files.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0238">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:openoffice:openoffice"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openoffice:openoffice</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0238</vuln:cve-id>
    <vuln:published-datetime>2007-03-21T15:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:31:53.667-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8968" name="oval:org.mitre.oval:def:8968"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0007.html" xml:lang="en">SUSE-SA:2007:023</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102794-1" xml:lang="en">102794</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1270" xml:lang="en">DSA-1270</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200704-12.xml" xml:lang="en">GLSA-200704-12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:073" xml:lang="en">MDKSA-2007:073</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.ngssoftware.com/advisories/high-risk-vulnerabilities-in-the-openoffice-suite/" xml:lang="en">http://www.ngssoftware.com/advisories/high-risk-vulnerabilities-in-the-openoffice-suite/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.openoffice.org/security/CVE-2007-0238" xml:lang="en">http://www.openoffice.org/security/CVE-2007-0238</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0033.html" xml:lang="en">RHSA-2007:0033</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0069.html" xml:lang="en">RHSA-2007:0069</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/464724/100/0/threaded" xml:lang="en">20070404 High Risk Vulnerability in OpenOffice</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23067" xml:lang="en">23067</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017799" xml:lang="en">1017799</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-444-1" xml:lang="en">USN-444-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1032" xml:lang="en">ADV-2007-1032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1117" xml:lang="en">ADV-2007-1117</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33112" xml:lang="en">openoffice-starcalc-bo(33112)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.foresightlinux.org/browse/FL-211" xml:lang="en">https://issues.foresightlinux.org/browse/FL-211</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1118" xml:lang="en">https://issues.rpath.com/browse/RPL-1118</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in filter\starcalc\scflt.cxx in the StarCalc parser in OpenOffice.org (OOo) Office Suite before 2.2, and 1.x before 1.1.5 Patch, allows user-assisted remote attackers to execute arbitrary code via a document with a long Note.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0239">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:openoffice:openoffice"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openoffice:openoffice</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0239</vuln:cve-id>
    <vuln:published-datetime>2007-03-21T15:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:36.017-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11422" name="oval:org.mitre.oval:def:11422"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0007.html" xml:lang="en">SUSE-SA:2007:023</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102807-1" xml:lang="en">102807</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1270" xml:lang="en">DSA-1270</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200704-12.xml" xml:lang="en">GLSA-200704-12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:073" xml:lang="en">MDKSA-2007:073</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0033.html" xml:lang="en">RHSA-2007:0033</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0069.html" xml:lang="en">RHSA-2007:0069</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22812" xml:lang="en">22812</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017799" xml:lang="en">1017799</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-444-1" xml:lang="en">USN-444-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1032" xml:lang="en">ADV-2007-1032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1117" xml:lang="en">ADV-2007-1117</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33113" xml:lang="en">openoffice-shell-command-execution(33113)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.foresightlinux.org/browse/FL-211" xml:lang="en">https://issues.foresightlinux.org/browse/FL-211</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1118" xml:lang="en">https://issues.rpath.com/browse/RPL-1118</vuln:reference>
    </vuln:references>
    <vuln:summary>OpenOffice.org (OOo) Office Suite allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a prepared link in a crafted document.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0240">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:zope:zope:2.10.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:zope:zope:2.10.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0240</vuln:cve-id>
    <vuln:published-datetime>2007-03-22T14:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:04.250-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-May/0005.html" xml:lang="en">SUSE-SR:2007:011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1275" xml:lang="en">DSA-1275</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23084" xml:lang="en">23084</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1041" xml:lang="en">ADV-2007-1041</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.zope.org/Products/Zope/Hotfix-2007-03-20/announcement/view" xml:lang="en">http://www.zope.org/Products/Zope/Hotfix-2007-03-20/announcement/view</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33187" xml:lang="en">zope-unspecifiedget-xss(33187)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Zope 2.10.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in a HTTP GET request.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0242">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:qt:qt:3.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:qt:qt:4.2.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:qt:qt:3.3.8</vuln:product>
      <vuln:product>cpe:/a:qt:qt:4.2.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0242</vuln:cve-id>
    <vuln:published-datetime>2007-04-03T12:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:36.110-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11510" name="oval:org.mitre.oval:def:11510"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070901-01-P.asc" xml:lang="en">20070901-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/updates/FEDORA-2007-703.shtml" xml:lang="en">FEDORA-2007-703</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2011-1324.html" xml:lang="en">RHSA-2011:1324</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.348591" xml:lang="en">SSA:2007-093-03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2007-424.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2007-424.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.novell.com/techcenter/psdb/39ea4b325a7da742cb8b6995fa585b14.html" xml:lang="en">http://support.novell.com/techcenter/psdb/39ea4b325a7da742cb8b6995fa585b14.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.novell.com/techcenter/psdb/fc79b7f48d739f9c803a24ddad933384.html" xml:lang="en">http://support.novell.com/techcenter/psdb/fc79b7f48d739f9c803a24ddad933384.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1292" xml:lang="en">DSA-1292</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:074" xml:lang="en">MDKSA-2007:074</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:075" xml:lang="en">MDKSA-2007:075</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:076" xml:lang="en">MDKSA-2007:076</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.nabble.com/Bug-417390:-CVE-2007-0242,--Qt-UTF-8-overlong-sequence-decoding-vulnerability-t3506065.html" xml:lang="en">http://www.nabble.com/Bug-417390:-CVE-2007-0242,--Qt-UTF-8-overlong-sequence-decoding-vulnerability-t3506065.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_6_sr.html" xml:lang="en">SUSE-SR:2007:006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0883.html" xml:lang="en">RHSA-2007:0883</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0909.html" xml:lang="en">RHSA-2007:0909</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23269" xml:lang="en">23269</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.trolltech.com/company/newsroom/announcements/press.2007-03-30.9172215350" xml:lang="en">http://www.trolltech.com/company/newsroom/announcements/press.2007-03-30.9172215350</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-452-1" xml:lang="en">USN-452-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1212" xml:lang="en">ADV-2007-1212</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33397" xml:lang="en">qt-utf8-xss(33397)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1202" xml:lang="en">https://issues.rpath.com/browse/RPL-1202</vuln:reference>
    </vuln:references>
    <vuln:summary>The UTF-8 decoder in codecs/qutfcodec.cpp in Qt 3.3.8 and 4.2.3 does not reject long UTF-8 sequences as required by the standard, which allows remote attackers to conduct cross-site scripting (XSS) and directory traversal attacks via long sequences that decode to dangerous metacharacters.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0243">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jdk:1.5.0:update9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1:update16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.3.1:update18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_11"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.4.2_12"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update4"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update5"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update6"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update7"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update8"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:jre:1.5.0:update9"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_01"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_01a"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_16"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.3.1_18"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_03"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_08"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_09"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_10"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:sdk:1.4.2_12"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update3</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update4</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update5</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update7</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update8</vuln:product>
      <vuln:product>cpe:/a:sun:jdk:1.5.0:update9</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1:update16</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.3.1:update18</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_1</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_2</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_3</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_4</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_5</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_6</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_8</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_9</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_10</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_11</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.4.2_12</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update3</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update4</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update5</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update6</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update7</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update8</vuln:product>
      <vuln:product>cpe:/a:sun:jre:1.5.0:update9</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_01</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_01a</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_16</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.3.1_18</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_03</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_08</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_09</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_10</vuln:product>
      <vuln:product>cpe:/a:sun:sdk:1.4.2_12</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0243</vuln:cve-id>
    <vuln:published-datetime>2007-01-17T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:21.780-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11073" name="oval:org.mitre.oval:def:11073"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BEA</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/pub/advisory/242" xml:lang="en">BEA07-172.00</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307177" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307177</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579" xml:lang="en">HPSBUX02196</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Dec/msg00001.html" xml:lang="en">APPLE-SA-2007-12-14</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200702-08.xml" xml:lang="en">GLSA-200702-08</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2158" xml:lang="en">2158</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017520" xml:lang="en">1017520</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102760-1" xml:lang="en">102760</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.novell.com/techcenter/psdb/4f850d1e2b871db609de64ec70f0089c.html" xml:lang="en">http://support.novell.com/techcenter/psdb/4f850d1e2b871db609de64ec70f0089c.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.novell.com/techcenter/psdb/d2f549cc040cd81ae4a268bb5edfe918.html" xml:lang="en">http://support.novell.com/techcenter/psdb/d2f549cc040cd81ae4a268bb5edfe918.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200702-07.xml" xml:lang="en">GLSA-200702-07</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/388289" xml:lang="en">VU#388289</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_45_java.html" xml:lang="en">SUSE-SA:2007:045</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0166.html" xml:lang="en">RHSA-2007:0166</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0167.html" xml:lang="en">RHSA-2007:0167</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0956.html" xml:lang="en">RHSA-2007:0956</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0261.html" xml:lang="en">RHSA-2008:0261</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457159/100/0/threaded" xml:lang="en">20070117 ZDI-07-005: Sun Microsystems Java GIF File Parsing Memory Corruption Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457638/100/0/threaded" xml:lang="en">20070121 Sun Microsystems Java GIF File Parsing Memory Corruption Vulnerability Prove Of Concept Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22085" xml:lang="en">22085</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-022A.html" xml:lang="en">TA07-022A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0211" xml:lang="en">ADV-2007-0211</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0936" xml:lang="en">ADV-2007-0936</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1814" xml:lang="en">ADV-2007-1814</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/4224" xml:lang="en">ADV-2007-4224</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-07-005.html" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-07-005.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31537" xml:lang="en">jre-gif-bo(31537)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Sun JDK and Java Runtime Environment (JRE) 5.0 Update 9 and earlier, SDK and JRE 1.4.2_12 and earlier, and SDK and JRE 1.3.1_18 and earlier allows applets to gain privileges via a GIF image with a block with a 0 width field, which triggers memory corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0244">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0"/>
          <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0::alpha"/>
          <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0::amd64"/>
          <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0::arm"/>
          <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0::hppa"/>
          <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0::ia-32"/>
          <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0::ia-64"/>
          <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0::m68k"/>
          <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0::mips"/>
          <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0::mipsel"/>
          <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0::powerpc"/>
          <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0::s390"/>
          <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0::sparc"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:poptop:pptp_server:1.3.3"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:poptop:pptp_server:1.3.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0244</vuln:cve-id>
    <vuln:published-datetime>2007-05-11T00:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:04.313-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200705-18.xml" xml:lang="en">GLSA-200705-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=501476&amp;group_id=44827" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=501476&amp;group_id=44827</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1288" xml:lang="en">DSA-1288</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_10_sr.html" xml:lang="en">SUSE-SR:2007:010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_19_sr.html" xml:lang="en">SUSE-SR:2007:019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23886" xml:lang="en">23886</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018064" xml:lang="en">1018064</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2007/0017/" xml:lang="en">2007-0017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-459-1" xml:lang="en">USN-459-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-459-2" xml:lang="en">USN-459-2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1743" xml:lang="en">ADV-2007-1743</vuln:reference>
    </vuln:references>
    <vuln:summary>pptpgre.c in PoPToP Point to Point Tunneling Server (pptpd) before 1.3.4 allows remote attackers to cause a denial of service (PPTP connection tear-down) via (1) GRE packets with out-of-order sequence numbers or (2) certain GRE packets that are processed using a wrong pointer and improperly dequeued.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0245">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:openoffice:openoffice:2.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openoffice:openoffice:2.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0245</vuln:cve-id>
    <vuln:published-datetime>2007-06-12T17:30:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:00.277-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10002" name="oval:org.mitre.oval:def:10002"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.asc" xml:lang="en">20070602-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102917-1" xml:lang="en">102917</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sw.openoffice.org/source/browse/sw/sw/source/filter/rtf/swparrtf.cxx?rev=1.67" xml:lang="en">http://sw.openoffice.org/source/browse/sw/sw/source/filter/rtf/swparrtf.cxx?rev=1.67</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1307" xml:lang="en">DSA-1307</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200707-02.xml" xml:lang="en">GLSA-200707-02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:144" xml:lang="en">MDKSA-2007:144</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_37_openoffice.html" xml:lang="en">SUSE-SA:2007:037</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0406.html" xml:lang="en">RHSA-2007:0406</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/471274/100/0/threaded" xml:lang="en">20070613 High risk vulnerability in OpenOffice RTF parser</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/24450" xml:lang="en">24450</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018239" xml:lang="en">1018239</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-482-1" xml:lang="en">USN-482-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2166" xml:lang="en">ADV-2007-2166</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2229" xml:lang="en">ADV-2007-2229</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/34843" xml:lang="en">openoffice-rtf-bo(34843)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1570" xml:lang="en">https://issues.rpath.com/browse/RPL-1570</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in OpenOffice.org (OOo) 2.2.1 and earlier allows remote attackers to execute arbitrary code via a RTF file with a crafted prtdata tag with a length parameter inconsistency, which causes vtable entries to be overwritten.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0246">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gforge:gforge:4.5.16"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gforge:gforge:4.5.16</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0246</vuln:cve-id>
    <vuln:published-datetime>2007-05-29T17:30:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:04.563-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://gforge.org/scm/viewvc.php/branches/Branch_4_5/gforge/plugins/scmcvs/www/cvsweb.php?root=gforge&amp;r1=5849&amp;r2=6038&amp;pathrev=6038" xml:lang="en">http://gforge.org/scm/viewvc.php/branches/Branch_4_5/gforge/plugins/scmcvs/www/cvsweb.php?root=gforge&amp;r1=5849&amp;r2=6038&amp;pathrev=6038</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1297" xml:lang="en">DSA-1297</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/24141" xml:lang="en">24141</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1942" xml:lang="en">ADV-2007-1942</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/34510" xml:lang="en">gforge-cvsweb-command-execution(34510)</vuln:reference>
    </vuln:references>
    <vuln:summary>plugins/scmcvs/www/cvsweb.php in the CVSWeb CGI in GForge 4.5.16 before 20070524, aka gforge-plugin-scmcvs, allows remote attackers to execute arbitrary commands via shell metacharacters in the PATH_INFO.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0247">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.6.stable1"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.6.stable2"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.6.stable3"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.6.stable4"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.6.stable5"/>
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.6.stable6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:squid:squid:2.6.stable1</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.6.stable2</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.6.stable3</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.6.stable4</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.6.stable5</vuln:product>
      <vuln:product>cpe:/a:squid:squid:2.6.stable6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0247</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:04.640-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200701-22.xml" xml:lang="en">GLSA-200701-22</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:026" xml:lang="en">MDKSA-2007:026</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_12_squid.html" xml:lang="en">SUSE-SA:2007:012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22079" xml:lang="en">22079</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.squid-cache.org/bugs/show_bug.cgi?id=1857" xml:lang="en">http://www.squid-cache.org/bugs/show_bug.cgi?id=1857</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.squid-cache.org/Versions/v2/2.6/squid-2.6.STABLE7-RELEASENOTES.html#s12" xml:lang="en">http://www.squid-cache.org/Versions/v2/2.6/squid-2.6.STABLE7-RELEASENOTES.html#s12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-414-1" xml:lang="en">USN-414-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0199" xml:lang="en">ADV-2007-0199</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31523" xml:lang="en">squid-multiple-dos(31523)</vuln:reference>
    </vuln:references>
    <vuln:summary>squid/src/ftp.c in Squid before 2.6.STABLE7 allows remote FTP servers to cause a denial of service (core dump) via crafted FTP directory listing responses, possibly related to the (1) ftpListingFinish and (2) ftpHtmlifyListEntry functions.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0248">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:squid:squid:2.6.stable6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:squid:squid:2.6.stable6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0248</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:04.703-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200701-22.xml" xml:lang="en">GLSA-200701-22</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:026" xml:lang="en">MDKSA-2007:026</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_12_squid.html" xml:lang="en">SUSE-SA:2007:012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22203" xml:lang="en">22203</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.squid-cache.org/bugs/show_bug.cgi?id=1848" xml:lang="en">http://www.squid-cache.org/bugs/show_bug.cgi?id=1848</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.squid-cache.org/Versions/v2/2.6/squid-2.6.STABLE7-RELEASENOTES.html#s12" xml:lang="en">http://www.squid-cache.org/Versions/v2/2.6/squid-2.6.STABLE7-RELEASENOTES.html#s12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-414-1" xml:lang="en">USN-414-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0199" xml:lang="en">ADV-2007-0199</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31525" xml:lang="en">squid-externalacl-dos(31525)</vuln:reference>
    </vuln:references>
    <vuln:summary>The aclMatchExternal function in Squid before 2.6.STABLE7 allows remote attackers to cause a denial of service (crash) by causing an external_acl queue overload, which triggers an infinite loop.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0249">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nwom:nwom_topsites:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nwom:nwom_topsites:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0249</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:03.103-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2149" xml:lang="en">2149</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456636/100/0/threaded" xml:lang="en">20070111 Nwom topsites v3.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22012" xml:lang="en">22012</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in index.php in Nwom topsites 3.0 allows remote attackers to inject arbitrary web script or HTML via the o parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0250">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nwom:nwom_topsites:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nwom:nwom_topsites:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0250</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:03.277-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2149" xml:lang="en">2149</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456636/100/0/threaded" xml:lang="en">20070111 Nwom topsites v3.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22012" xml:lang="en">22012</vuln:reference>
    </vuln:references>
    <vuln:summary>index.php in Nwom topsites 3.0 allows remote attackers to obtain potentially sensitive information via a ' (quote) character in the o parameter, which forces a SQL error.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0251">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:snort:snort:2.6.1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:snort:snort:2.6.1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0251</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:03.433-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://labs.calyptix.com/advisories/CX-2007-01.txt" xml:lang="en">http://labs.calyptix.com/advisories/CX-2007-01.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2165" xml:lang="en">2165</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017507" xml:lang="en">1017507</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456598/100/0/threaded" xml:lang="en">20070111 Calyptix Security Advisory CX-2007-001 - Snort 2.6.1.2 Integer Underflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22004" xml:lang="en">22004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.snort.org/got_source/source.html" xml:lang="en">http://www.snort.org/got_source/source.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0152" xml:lang="en">ADV-2007-0152</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer underflow in the DecodeGRE function in src/decode.c in Snort 2.6.1.2 allows remote attackers to trigger dereferencing of certain memory locations via crafted GRE packets, which may cause corruption of log files or writing of sensitive information into log files.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0252">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:easy-content_filemanager:easy-content_filemanager"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:easy-content_filemanager:easy-content_filemanager</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0252</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:03.837-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456622/100/0/threaded" xml:lang="en">20070111 easy-content filemanager</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in easy-content filemanager allows remote attackers to upload or modify arbitrary files via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0253">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:grsecurity:grsecurity_kernel_patch"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:grsecurity:grsecurity_kernel_patch</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0253</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:17:24.447-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-17T10:25:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://forums.grsecurity.net/viewtopic.php?t=1646" xml:lang="en">http://forums.grsecurity.net/viewtopic.php?t=1646</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://grsecurity.net/news.php#digitalfud" xml:lang="en">http://grsecurity.net/news.php#digitalfud</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.digitalarmaments.com/news_news.shtml" xml:lang="en">http://www.digitalarmaments.com/news_news.shtml</vuln:reference>
    </vuln:references>
    <vuln:summary>** DISPUTED **  Unspecified vulnerability in the grsecurity patch has unspecified impact and remote attack vectors, a different vulnerability than the expand_stack vulnerability from the Digital Armaments 20070110 pre-advisory.  NOTE: the grsecurity developer has disputed this issue, stating that "the function they claim the vulnerability to be in is a trivial function, which can, and has been, easily checked for any supposed vulnerabilities."  The developer also cites a past disclosure that was not proven.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0254">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:xine:xine-ui"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xine:xine-ui</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0254</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:03.963-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200701-18.xml" xml:lang="en">GLSA-200701-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:027" xml:lang="en">MDKSA-2007:027</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:154" xml:lang="en">MDKSA-2007:154</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456590/100/0/threaded" xml:lang="en">20070111 Xine-ui format string Vulnerabilties.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22002" xml:lang="en">22002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31505" xml:lang="en">xineui-errorscreatewindow-format-string(31505)</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in the errors_create_window function in errors.c in xine-ui allows attackers to execute arbitrary code via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0255">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:xine:xine:0.99.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xine:xine:0.99.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0255</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:04.557-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:027" xml:lang="en">MDKSA-2007:027</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:154" xml:lang="en">MDKSA-2007:154</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456523/100/0/threaded" xml:lang="en">20070110 VLC Format String Vulnerability also in XINE</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22252" xml:lang="en">22252</vuln:reference>
    </vuln:references>
    <vuln:summary>XINE 0.99.4 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a certain M3U file that contains a long #EXTINF line and contains format string specifiers in an invalid udp:// URI, possibly a variant of CVE-2007-0017.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0256">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:videolan:vlc_media_player:0.8.6a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:videolan:vlc_media_player:0.8.6a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0256</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:36.347-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14698" name="oval:org.mitre.oval:def:14698"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://downloads.securityfocus.com/vulnerabilities/exploits/22003.py" xml:lang="en">http://downloads.securityfocus.com/vulnerabilities/exploits/22003.py</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://wiki.videolan.org/Changelog/0.8.6b" xml:lang="en">http://wiki.videolan.org/Changelog/0.8.6b</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22003" xml:lang="en">22003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31515" xml:lang="en">vlcmediaplayer-wmv-dos(31515)</vuln:reference>
    </vuln:references>
    <vuln:summary>VideoLAN VLC 0.8.6a allows remote attackers to cause a denial of service (application crash) via a crafted .wmv file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0257">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:grsecurity:grsecurity_kernel_patch:1.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:grsecurity:grsecurity_kernel_patch:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:grsecurity:grsecurity_kernel_patch:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:grsecurity:grsecurity_kernel_patch:2.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:grsecurity:grsecurity_kernel_patch:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:grsecurity:grsecurity_kernel_patch:2.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:grsecurity:grsecurity_kernel_patch:2.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:grsecurity:grsecurity_kernel_patch:2.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:grsecurity:grsecurity_kernel_patch:2.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:grsecurity:grsecurity_kernel_patch:2.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:grsecurity:grsecurity_kernel_patch:2.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:grsecurity:grsecurity_kernel_patch:2.1.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:grsecurity:grsecurity_kernel_patch:1.9.4</vuln:product>
      <vuln:product>cpe:/a:grsecurity:grsecurity_kernel_patch:2.0.1</vuln:product>
      <vuln:product>cpe:/a:grsecurity:grsecurity_kernel_patch:2.0.2</vuln:product>
      <vuln:product>cpe:/a:grsecurity:grsecurity_kernel_patch:2.1.0</vuln:product>
      <vuln:product>cpe:/a:grsecurity:grsecurity_kernel_patch:2.1.1</vuln:product>
      <vuln:product>cpe:/a:grsecurity:grsecurity_kernel_patch:2.1.2</vuln:product>
      <vuln:product>cpe:/a:grsecurity:grsecurity_kernel_patch:2.1.3</vuln:product>
      <vuln:product>cpe:/a:grsecurity:grsecurity_kernel_patch:2.1.4</vuln:product>
      <vuln:product>cpe:/a:grsecurity:grsecurity_kernel_patch:2.1.5</vuln:product>
      <vuln:product>cpe:/a:grsecurity:grsecurity_kernel_patch:2.1.6</vuln:product>
      <vuln:product>cpe:/a:grsecurity:grsecurity_kernel_patch:2.1.7</vuln:product>
      <vuln:product>cpe:/a:grsecurity:grsecurity_kernel_patch:2.1.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0257</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:04.823-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://forums.grsecurity.net/viewtopic.php?t=1646" xml:lang="en">http://forums.grsecurity.net/viewtopic.php?t=1646</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://grsecurity.net/news.php#digitalfud" xml:lang="en">http://grsecurity.net/news.php#digitalfud</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017509" xml:lang="en">1017509</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.digitalarmaments.com/news_news.shtml" xml:lang="en">http://www.digitalarmaments.com/news_news.shtml</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.digitalarmaments.com/pre2007-00018659.html" xml:lang="en">http://www.digitalarmaments.com/pre2007-00018659.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456626/100/0/threaded" xml:lang="en">20070111 Digital Armaments Security Pre-Advisory 11.01.2007: Grsecurity Kernel PaX - Local root vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456722/100/0/threaded" xml:lang="en">20070112 Lies? [Was: Re: Digital Armaments Security Pre-Advisory11.01.2007: Grsecurity Kernel PaX - Local root vulnerability]</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457509/100/0/threaded" xml:lang="en">20070120 Digital Armaments Security Advisory 20.01.2007: Grsecurity Kernel PaX Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/462302/100/100/threaded" xml:lang="en">20070309 Re: Digital Armaments Security Advisory 20.01.2007: Grsecurity Kernel PaX Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22014" xml:lang="en">22014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0155" xml:lang="en">ADV-2007-0155</vuln:reference>
    </vuln:references>
    <vuln:summary>** DISPUTED **  Unspecified vulnerability in the expand_stack function in grsecurity PaX allows local users to gain privileges via unspecified vectors. NOTE: the grsecurity developer has disputed this issue, stating that "the function they claim the vulnerability to be in is a trivial function, which can, and has been, easily checked for any supposed vulnerabilities."  The developer also cites a past disclosure that was not proven.  As of 20070120, the original researcher has released demonstration code.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0258">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:fastilo:fastilo:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:opensolution:quick.car:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:fastilo:fastilo:2.0</vuln:product>
      <vuln:product>cpe:/a:opensolution:quick.car:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0258</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:04.890-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://14house.blogspot.com/2007/01/fastilo-open-source-shopping-cart-vuln.html" xml:lang="en">http://14house.blogspot.com/2007/01/fastilo-open-source-shopping-cart-vuln.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/21971" xml:lang="en">21971</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22007" xml:lang="en">22007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0156" xml:lang="en">ADV-2007-0156</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0157" xml:lang="en">ADV-2007-0157</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31475" xml:lang="en">quickcart-p-xss(31475)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in index.php in (1) Fastilo 2.0 and (2) Open Solution Quick.Cart 2.0 allows remote attackers to inject arbitrary web script or HTML via the p parameter.  NOTE: some of these details are obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0259">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ezboxx:ezboxx_portal_system:beta_0.7.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ezboxx:ezboxx_portal_system:beta_0.7.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0259</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:05.573-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.bugsec.com/articles.php?Security=20" xml:lang="en">http://www.bugsec.com/articles.php?Security=20</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456699/100/0/threaded" xml:lang="en">20070111 Ezboxx multiple vulnerabilities.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0208" xml:lang="en">ADV-2007-0208</vuln:reference>
    </vuln:references>
    <vuln:summary>Ezboxx Portal System Beta 0.7.6 and earlier allows remote attackers to obtain sensitive information via an invalid cat parameter to boxx/knowledgebase.asp, which reveals the path in an error message.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0260">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:naig:naig:0.5.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:naig:naig:0.5.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0260</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:05.790-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2145" xml:lang="en">2145</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-January/001239.html" xml:lang="en">20070112 Fwd: Naig &lt;= 0.5.2 (this_path) Remote File Include Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456744/100/0/threaded" xml:lang="en">20070112 Naig &lt;= 0.5.2 (this_path) Remote File Include Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456785/100/0/threaded" xml:lang="en">20070113 Re: Naig &lt;= 0.5.2 (this_path) Remote File Include Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>** DISPUTED **  PHP remote file inclusion vulnerability in index.php in Naig 0.5.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the this_path parameter.  NOTE: a reliable third party disputes this vulnerability because this_path is defined before use.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0261">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:snews:snews:1.5.29"/>
        <cpe-lang:fact-ref name="cpe:/a:snews:snews:1.5.30"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:snews:snews:1.5.29</vuln:product>
      <vuln:product>cpe:/a:snews:snews:1.5.30</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0261</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:57.940-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22025" xml:lang="en">22025</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31535" xml:lang="en">snews-image-file-upload(31535)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3116" xml:lang="en">3116</vuln:reference>
    </vuln:references>
    <vuln:summary>snews.php in sNews 1.5.30 and earlier does not properly exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, as demonstrated by changing an administrative password via the changeup task, and by uploading PHP code via the imagefile parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0262">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.1:alpha_3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.6</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.1:alpha_3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0262</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:06.027-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456731/100/0/threaded" xml:lang="en">20070112 Wordpress disclosure of Table Prefix Weakness</vuln:reference>
    </vuln:references>
    <vuln:summary>WordPress 2.0.6, and 2.1Alpha 3 (SVN:4662), does not properly verify that the m parameter value has the string data type, which allows remote attackers to obtain sensitive information via an invalid m[] parameter, as demonstrated by obtaining the path, and obtaining certain SQL information such as the table prefix.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0263">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:total_commander:total_commander:6.5.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:total_commander:total_commander:6.5.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0263</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:39:35.517-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.ghisler.com/whatsnew.htm" xml:lang="en">http://www.ghisler.com/whatsnew.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22033" xml:lang="en">22033</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Total Commander before 6.5.6 allows user-assisted remote attackers to delete arbitrary files and corrupt a filesystem via a crafted RAR file.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0264">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:winzip:winzip:9.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:winzip:winzip:9.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0264</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:39:35.627-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22020" xml:lang="en">22020</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Winzip32.exe in WinZip 9.0 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long command line argument.  NOTE: this issue may cross privilege boundaries if an application automatically invokes Winzip32.exe for untrusted input filenames, as in the case of a file upload application.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0265">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ezboxx:portal_system_beta:0.7.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ezboxx:portal_system_beta:0.7.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0265</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:06.137-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.bugsec.com/articles.php?Security=20" xml:lang="en">http://www.bugsec.com/articles.php?Security=20</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456699/100/0/threaded" xml:lang="en">20070111 Ezboxx multiple vulnerabilities.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0208" xml:lang="en">ADV-2007-0208</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Ezboxx Portal System Beta 0.7.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the pic parameter to custom/piczoom.asp, (2) the nocatname parameter to boxx/user-upload.asp, or (3) the iid parameter to indexes/newscomments.asp.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0266">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ezboxx:ezboxx_portal_system:beta_0.7.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ezboxx:ezboxx_portal_system:beta_0.7.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0266</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:06.573-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.bugsec.com/articles.php?Security=20" xml:lang="en">http://www.bugsec.com/articles.php?Security=20</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456699/100/0/threaded" xml:lang="en">20070111 Ezboxx multiple vulnerabilities.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0208" xml:lang="en">ADV-2007-0208</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in boxx/ShowAppendix.asp in Ezboxx Portal System Beta 0.7.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the iid parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0267">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:6.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0267</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-06-10T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-17T11:27:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305214" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" xml:lang="en">APPLE-SA-2007-03-13</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.freebsd.org/pipermail/freebsd-security/2007-January/004218.html" xml:lang="en">[freebsd-security] 20070114 MOAB advisories</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-12-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-12-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22036" xml:lang="en">22036</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017751" xml:lang="en">1017751</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" xml:lang="en">TA07-072A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0171" xml:lang="en">ADV-2007-0171</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0930" xml:lang="en">ADV-2007-0930</vuln:reference>
    </vuln:references>
    <vuln:summary>The ufs_lookup function in the Mac OS X 10.4.8 and FreeBSD 6.1 kernels allows local users to cause a denial of service (kernel panic) and possibly corrupt other filesystems by mounting a crafted UNIX File System (UFS) DMG image that contains a corrupted directory entry (struct direct), related to the ufs_dirbad function.  NOTE: a third party states that the FreeBSD issue does not cross privilege boundaries.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0268">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:9.0.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:9.2.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:10.1.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:database_server:9.0.1.5</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:9.2.0.7</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:10.1.0.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0268</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:06.853-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017522" xml:lang="en">1017522</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/221788" xml:lang="en">VU#221788</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.red-database-security.com/advisory/oracle_sql_injection_dbms_aq_inv.html" xml:lang="en">http://www.red-database-security.com/advisory/oracle_sql_injection_dbms_aq_inv.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458005/100/0/threaded" xml:lang="en">20070124 Oracle Buffer Overflow in DBMS_REPCAT_UNTRUSTED.UNREGISTER_SNAPSHOT</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458475/100/100/threaded" xml:lang="en">20070129 Re: Re: Oracle Buffer Overflows in DBMS_CAPTURE_ADM_INTERNAL</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22083" xml:lang="en">22083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" xml:lang="en">TA07-017A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31541" xml:lang="en">oracle-cpu-jan2007(31541)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5, 9.2.0.7, and 10.1.0.5 have unknown impact and attack vectors related to (1) the Advanced Queuing component and sys.dbms_aqsys.dbms_aq privileges (DB01), (2) Advanced Replication and sys.dbms_repcat_untrusted (DB07), and (3) Oracle Text and ctxload (DB15).  NOTE: Oracle has not publicly claims by reliable researchers that DB01 is for SQL injection in the SYS.DBMS_AQ_INV package, and DB07 is for a buffer overflow in the UNREGISTER_SNAPSHOT procedure in the DBMS_REPCAT_UNTRUSTED package.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0269">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:9.2.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:10.1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:10.2.0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:database_server:9.2.0.8</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:10.1.0.5</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:10.2.0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0269</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:05.047-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017522" xml:lang="en">1017522</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22083" xml:lang="en">22083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" xml:lang="en">TA07-017A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31541" xml:lang="en">oracle-cpu-jan2007(31541)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3 has unknown impact and attack vectors related to the Change Data Capture and sys.dbms_cdc_subscribe privileges, aka DB02.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0270">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:9.2.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:10.1.0.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:database_server:9.2.0.7</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:10.1.0.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0270</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:07.620-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017522" xml:lang="en">1017522</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.appsecinc.com/resources/alerts/oracle/2007-04.shtml" xml:lang="en">http://www.appsecinc.com/resources/alerts/oracle/2007-04.shtml</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458036/100/0/threaded" xml:lang="en">20070124 Oracle Buffer Overflow in DBMS_DRS.GET_PROPERTY</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/474050/100/0/threaded" xml:lang="en">20070718 Oracle Database Buffer overflow vulnerabilities in procedure DBMS_DRS.GET_PROPERTY (DB03)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22083" xml:lang="en">22083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" xml:lang="en">TA07-017A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31541" xml:lang="en">oracle-cpu-jan2007(31541)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in SYS.DBMS_DRS in Oracle Database 9.2.0.7 and 10.1.0.4 allows remote authenticated users to cause a denial of service (crash) or execute arbitrary code via the GET_PROPERTY function in SYS.DBMS_DRS, aka DB03.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0271">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:9.0.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:9.2.0.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:database_server:9.0.1.5</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:9.2.0.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0271</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:08.370-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017522" xml:lang="en">1017522</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.appsecinc.com/resources/alerts/oracle/2007-01.shtml" xml:lang="en">http://www.appsecinc.com/resources/alerts/oracle/2007-01.shtml</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458006/100/0/threaded" xml:lang="en">20070124 Oracle Buffer Overflow in DBMS_LOGMNR.ADD_LOGFILE</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458475/100/100/threaded" xml:lang="en">20070129 Re: Re: Oracle Buffer Overflows in DBMS_CAPTURE_ADM_INTERNAL</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22083" xml:lang="en">22083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" xml:lang="en">TA07-017A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31541" xml:lang="en">oracle-cpu-jan2007(31541)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Oracle Database 9.0.1.5 and 9.2.0.7 has unknown impact and attack vectors related to the Log Miner component and sys.dbms_log_mnr privileges, aka DB04.  NOTE: Oracle has not disputed a reliable researcher claim that this is a buffer overflow in the ADD_LOGFILE procedure for the SYS.DBMS_LOGMNR package that allows code execution.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0272">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:8.1.7.4"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:9.0.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:9.2.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:10.1.0.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:database_server:8.1.7.4</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:9.0.1.5</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:9.2.0.7</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:10.1.0.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0272</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:09.057-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>8.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017522" xml:lang="en">1017522</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.appsecinc.com/resources/alerts/oracle/2007-05.shtml" xml:lang="en">http://www.appsecinc.com/resources/alerts/oracle/2007-05.shtml</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458038/100/0/threaded" xml:lang="en">20070124 Oracle Multiple Buffer Overflows and DoS attacks in public procedures of MDSYS.MD</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/474047/100/0/threaded" xml:lang="en">20070718 Oracle Database Buffer overflows and Denial of service vulnerabilities in public procedures of MDSYS.MD (DB12)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22083" xml:lang="en">22083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" xml:lang="en">TA07-017A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31541" xml:lang="en">oracle-cpu-jan2007(31541)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in MDSYS.MD in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 allows remote authenticated users to cause a denial of service (crash) or execute arbitrary code via unspecified vectors involving certain public procedures, aka DB05.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0273">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:9.0.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:9.2.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:10.1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:10.2.0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:database_server:9.0.1.5</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:9.2.0.8</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:10.1.0.5</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:10.2.0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0273</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:05.297-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017522" xml:lang="en">1017522</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.red-database-security.com/advisory/oracle_xmldb_css2.html" xml:lang="en">http://www.red-database-security.com/advisory/oracle_xmldb_css2.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22083" xml:lang="en">22083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" xml:lang="en">TA07-017A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31541" xml:lang="en">oracle-cpu-jan2007(31541)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Oracle Database 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.3 has unknown impact and attack vectors related to XMLDB, aka DB06.  NOTE: as of 20070123, Oracle has not disputed claims by a reliable researcher that DB06 is for multiple cross-site scripting (XSS) vulnerabilities.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0274">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:9.2.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:10.1.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:database_server:9.2.0.7</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:10.1.0.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0274</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:09.730-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017522" xml:lang="en">1017522</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458037/100/0/threaded" xml:lang="en">20070124 Oracle Buffer Overflow in DBMS_LOGREP_UTIL.GET_OBJECT_NAME</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458041/100/0/threaded" xml:lang="en">20070124 Oracle Buffer Overflows in DBMS_CAPTURE_ADM_INTERNAL</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458112/100/100/threaded" xml:lang="en">20070125 Re: Oracle Buffer Overflows in DBMS_CAPTURE_ADM_INTERNAL</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458126/100/0/threaded" xml:lang="en">20070125 Re: Oracle Buffer Overflow in DBMS_LOGREP_UTIL.GET_OBJECT_NAME</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458475/100/100/threaded" xml:lang="en">20070129 Re: Re: Oracle Buffer Overflows in DBMS_CAPTURE_ADM_INTERNAL</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22083" xml:lang="en">22083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" xml:lang="en">TA07-017A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31541" xml:lang="en">oracle-cpu-jan2007(31541)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple unspecified vulnerabilities in Oracle Database 9.2.0.7 and 10.1.0.5 have unknown impact and attack vectors related to (1) Export and sys.dbms_logrep_util (DB08), and (2) Oracle Streams and sys.dbms_capture_adm_internal privileges (DB09).  NOTE: Oracle has not disputed reliable researcher claims that DB08 is for a buffer overflow in the GET_OBJECT_NAME procedure in the DBMS_LOGREP_UTIL package, and DB09 is for buffer overflows in the CREATE_CAPTURE, ALTER_CAPTURE, and ABORT_TABLE_INSTANTIATION procedures in SYS.DBMS_CAPTURE_ADM_INTERNAL.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0275">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:application_server:9.0.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:application_server:10.1.2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:application_server:10.1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:collaboration_suite:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:9.2.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:10.1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:10.2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:e-business_suite:11.5.10.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:application_server:9.0.4.3</vuln:product>
      <vuln:product>cpe:/a:oracle:application_server:10.1.2.0.2</vuln:product>
      <vuln:product>cpe:/a:oracle:application_server:10.1.2.2</vuln:product>
      <vuln:product>cpe:/a:oracle:collaboration_suite:10.1.2</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:9.2.0.8</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:10.1.0.5</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:10.2.0.3</vuln:product>
      <vuln:product>cpe:/a:oracle:e-business_suite:11.5.10.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0275</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:10.620-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017522" xml:lang="en">1017522</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457193/100/0/threaded" xml:lang="en">20070117 [ISecAuditors Security Advisories] Oracle Reports Web Cartridge (RWCGI60) vulnerable to XSS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22083" xml:lang="en">22083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" xml:lang="en">TA07-017A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31541" xml:lang="en">oracle-cpu-jan2007(31541)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Oracle Reports Web Cartridge (RWCGI60) in the Workflow Cartridge component, as used in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3; Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2; Collaboration Suite 10.1.2; and Oracle E-Business Suite and Applications 11.5.10CU2; allows remote authenticated users to inject arbitrary HTML or web script via the genuser parameter to rwcgi60, aka OWF01.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0276">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:8.1.7.4"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:9.0.1.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:database_server:8.1.7.4</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:9.0.1.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0276</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:05.500-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017522" xml:lang="en">1017522</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22083" xml:lang="en">22083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" xml:lang="en">TA07-017A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31541" xml:lang="en">oracle-cpu-jan2007(31541)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple unspecified vulnerabilities in Oracle Database 8.1.7.4 and 9.0.1.5 have unknown impact and attack vectors related to (1) Advanced Security Option and oklist or okdstry (DB10), (2) Oracle Net Services (DB13), and (3) Recovery Manager and oklist (DB16).</vuln:summary>
  </entry>
  <entry id="CVE-2007-0277">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:10.1.0.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:database_server:10.1.0.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0277</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:05.547-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017522" xml:lang="en">1017522</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22083" xml:lang="en">22083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" xml:lang="en">TA07-017A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31541" xml:lang="en">oracle-cpu-jan2007(31541)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Oracle Database client-only 10.1.0.4 has unknown impact and attack vectors related to the Export component and expdp or impdp, aka DB11.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0278">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:8.1.7.4"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:9.0.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:9.2.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:database_server:10.1.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:database_server:8.1.7.4</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:9.0.1.5</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:9.2.0.7</vuln:product>
      <vuln:product>cpe:/a:oracle:database_server:10.1.0.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0278</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:05.610-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017522" xml:lang="en">1017522</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22083" xml:lang="en">22083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" xml:lang="en">TA07-017A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31541" xml:lang="en">oracle-cpu-jan2007(31541)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple unspecified vulnerabilities in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.5 have unknown impact and attack vectors related to (1) NLS Runtime and lmsgen (DB12), and (2) Oracle Text and ctxkbtc (DB14).</vuln:summary>
  </entry>
  <entry id="CVE-2007-0279">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:e-business_suite:11.5.10.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:http_server:9.2.0.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:e-business_suite:11.5.10.2</vuln:product>
      <vuln:product>cpe:/a:oracle:http_server:9.2.0.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0279</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:05.673-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017522" xml:lang="en">1017522</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22083" xml:lang="en">22083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" xml:lang="en">TA07-017A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31541" xml:lang="en">oracle-cpu-jan2007(31541)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple unspecified vulnerabilities in Oracle HTTP Server 9.2.0.8 and Oracle E-Business Suite and Applications 11.5.10CU2 have unknown impact and attack vectors, aka (1) OHS01, (2) OHS02, (3) OHS05, (4) OHS06, and (5) OHS07.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0280">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:application_server:9.0.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:application_server:10.1.2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:application_server:10.1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:collaboration_suite:9.0.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:collaboration_suite:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:http_server:9.0.1.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:application_server:9.0.4.3</vuln:product>
      <vuln:product>cpe:/a:oracle:application_server:10.1.2.0.2</vuln:product>
      <vuln:product>cpe:/a:oracle:application_server:10.1.2.2</vuln:product>
      <vuln:product>cpe:/a:oracle:collaboration_suite:9.0.4.2</vuln:product>
      <vuln:product>cpe:/a:oracle:collaboration_suite:10.1.2</vuln:product>
      <vuln:product>cpe:/a:oracle:http_server:9.0.1.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0280</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:05.720-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017522" xml:lang="en">1017522</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.red-database-security.com/advisory/oracle_buffer_overflow_ons.html" xml:lang="en">http://www.red-database-security.com/advisory/oracle_buffer_overflow_ons.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22083" xml:lang="en">22083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" xml:lang="en">TA07-017A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31541" xml:lang="en">oracle-cpu-jan2007(31541)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Oracle HTTP Server 9.0.1.5, Application Server 9.0.4.3, 10.1.2.0.0, 10.1.2.0.2, and 10.1.2.2; and Collaboration Suite 9.0.4.2 and 10.1.2; has unknown impact and attack vectors related to the Oracle Process Mgmt &amp; Notification component, aka OPMN01.   NOTE: as of 20070123, Oracle has not disputed claims by a reliable researcher that OPMN01 is for a buffer overflow in Oracle Notification Service (ONS).</vuln:summary>
  </entry>
  <entry id="CVE-2007-0281">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:application_server:9.0.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:application_server:10.1.2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:application_server:10.1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:collaboration_suite:9.0.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:collaboration_suite:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:http_server:9.0.1.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:application_server:9.0.4.3</vuln:product>
      <vuln:product>cpe:/a:oracle:application_server:10.1.2.0.2</vuln:product>
      <vuln:product>cpe:/a:oracle:application_server:10.1.2.2</vuln:product>
      <vuln:product>cpe:/a:oracle:collaboration_suite:9.0.4.2</vuln:product>
      <vuln:product>cpe:/a:oracle:collaboration_suite:10.1.2</vuln:product>
      <vuln:product>cpe:/a:oracle:http_server:9.0.1.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0281</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:05.780-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017522" xml:lang="en">1017522</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22083" xml:lang="en">22083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" xml:lang="en">TA07-017A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31541" xml:lang="en">oracle-cpu-jan2007(31541)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple unspecified vulnerabilities in Oracle HTTP Server 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.3; Application Server 9.0.4.3, 10.1.2.0.0, 10.1.2.0.1, 10.1.2.0.2, 10.1.2.1, and 10.1.3.0; and Collaboration Suite 9.0.4.2 and 10.1.2; have unknown impact and attack vectors related to the Oracle HTTP Server, aka (1) OHS03 and (2) OHS04.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0282">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:application_server:9.0.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:application_server:10.1.2.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:collaboration_suite:9.0.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:http_server:9.0.1.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:application_server:9.0.4.3</vuln:product>
      <vuln:product>cpe:/a:oracle:application_server:10.1.2.0.0</vuln:product>
      <vuln:product>cpe:/a:oracle:collaboration_suite:9.0.4.2</vuln:product>
      <vuln:product>cpe:/a:oracle:http_server:9.0.1.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0282</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:05.843-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017522" xml:lang="en">1017522</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22083" xml:lang="en">22083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" xml:lang="en">TA07-017A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31541" xml:lang="en">oracle-cpu-jan2007(31541)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Oracle HTTP Server 9.0.1.5, Application Server 9.0.4.2 and 10.1.2.0.0, and Collaboration Suite 9.0.4.2 has unknown impact and attack vectors related to the Oracle Process Mgmt &amp; Notification component, aka OPMN02.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0283">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:application_server:9.0.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:collaboration_suite:9.0.4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:application_server:9.0.4.3</vuln:product>
      <vuln:product>cpe:/a:oracle:collaboration_suite:9.0.4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0283</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:05.890-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017522" xml:lang="en">1017522</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22083" xml:lang="en">22083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" xml:lang="en">TA07-017A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31541" xml:lang="en">oracle-cpu-jan2007(31541)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Oracle Application Server 9.0.4.3 and Collaboration Suite 9.0.4.2 has unknown impact and attack vectors related to Oracle Containers for J2EE, aka OC4J02.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0284">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:application_server:9.0.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:application_server:10.1.2.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:collaboration_suite:9.0.4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:application_server:9.0.4.3</vuln:product>
      <vuln:product>cpe:/a:oracle:application_server:10.1.2.0.0</vuln:product>
      <vuln:product>cpe:/a:oracle:collaboration_suite:9.0.4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0284</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:05.953-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017522" xml:lang="en">1017522</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22083" xml:lang="en">22083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" xml:lang="en">TA07-017A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31541" xml:lang="en">oracle-cpu-jan2007(31541)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple unspecified vulnerabilities in Oracle Application Server 9.0.4.3 and 10.1.2.0.0, and Collaboration Suite 9.0.4.2, have unknown impact and attack vectors related to Oracle Containers for J2EE, aka (1) OC4J03 and (2) OC4J04.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0285">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:application_server:9.0.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:application_server:10.1.2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:application_server:10.1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:collaboration_suite:9.0.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:collaboration_suite:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:e-business_suite:11.5.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:application_server:9.0.4.3</vuln:product>
      <vuln:product>cpe:/a:oracle:application_server:10.1.2.0.2</vuln:product>
      <vuln:product>cpe:/a:oracle:application_server:10.1.2.2</vuln:product>
      <vuln:product>cpe:/a:oracle:collaboration_suite:9.0.4.2</vuln:product>
      <vuln:product>cpe:/a:oracle:collaboration_suite:10.1.2</vuln:product>
      <vuln:product>cpe:/a:oracle:e-business_suite:11.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0285</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:06.017-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017522" xml:lang="en">1017522</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22083" xml:lang="en">22083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" xml:lang="en">TA07-017A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31541" xml:lang="en">oracle-cpu-jan2007(31541)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Oracle Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2; Collaboration Suite 9.0.4.2 and 10.1.2; and E-Business Suite and Applications 11.5.10CU2 has unknown impact and attack vectors related to Oracle Reports Developer, aka REP01.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0286">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:application_server:10.1.2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:application_server:10.1.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:collaboration_suite:10.1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:application_server:10.1.2.0.2</vuln:product>
      <vuln:product>cpe:/a:oracle:application_server:10.1.3.0</vuln:product>
      <vuln:product>cpe:/a:oracle:collaboration_suite:10.1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0286</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:06.077-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017522" xml:lang="en">1017522</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22083" xml:lang="en">22083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" xml:lang="en">TA07-017A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31541" xml:lang="en">oracle-cpu-jan2007(31541)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Oracle Application Server 10.1.2.0.2 and 10.1.3.0, and Collaboration Suite 10.1.2, has unknown impact and attack vectors related to Containers for J2EE, aka OC4J07.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0287">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:application_server:9.0.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:application_server:10.1.2.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:application_server:10.1.2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:collaboration_suite:9.0.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:collaboration_suite:10.1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:application_server:9.0.4.3</vuln:product>
      <vuln:product>cpe:/a:oracle:application_server:10.1.2.0.0</vuln:product>
      <vuln:product>cpe:/a:oracle:application_server:10.1.2.0.2</vuln:product>
      <vuln:product>cpe:/a:oracle:collaboration_suite:9.0.4.2</vuln:product>
      <vuln:product>cpe:/a:oracle:collaboration_suite:10.1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0287</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:06.140-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>1.7</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017522" xml:lang="en">1017522</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22083" xml:lang="en">22083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" xml:lang="en">TA07-017A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31541" xml:lang="en">oracle-cpu-jan2007(31541)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Oracle Application Server 9.0.4.3, 10.1.2.0.0, and 10.1.2.0.2; and Collaboration Suite 9.0.4.2 and 10.1.2; has unknown impact and attack vectors related to Containers for J2EE, aka OC4J08.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0288">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:application_server:10.1.4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:application_server:10.1.4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0288</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:06.187-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>1.7</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017522" xml:lang="en">1017522</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22083" xml:lang="en">22083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" xml:lang="en">TA07-017A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31541" xml:lang="en">oracle-cpu-jan2007(31541)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Oracle Application Server 10.1.4.0 has unknown impact and attack vectors related to Oracle Internet Directory, aka OID01.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0289">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:application_server:9.0.4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:application_server:9.0.4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0289</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:06.250-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017522" xml:lang="en">1017522</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22083" xml:lang="en">22083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" xml:lang="en">TA07-017A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31541" xml:lang="en">oracle-cpu-jan2007(31541)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple unspecified vulnerabilities in Oracle Collaboration Suite 9.0.4.2 have unknown impact and attack vectors related to Oracle Containers for J2EE, aka (1) OC4J01, (2) OC4J05, and (3) OC4J06.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0290">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:e-business_suite:11.5.10.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:e-business_suite:11.5.10.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0290</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:06.297-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017522" xml:lang="en">1017522</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22083" xml:lang="en">22083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" xml:lang="en">TA07-017A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31541" xml:lang="en">oracle-cpu-jan2007(31541)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.10CU2 have unknown impact and attack vectors related to (1) Application Object Library (APPS01), (2) Human Resources (APPS03), (3) Payables (APPS04), (4) Trading Community Architecture (APPS05), and (5) Web Applications Desktop Integrator (APPS06).</vuln:summary>
  </entry>
  <entry id="CVE-2007-0291">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:e-business_suite:6.2.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:e-business_suite:6.2.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0291</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:06.360-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017522" xml:lang="en">1017522</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22083" xml:lang="en">22083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" xml:lang="en">TA07-017A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31541" xml:lang="en">oracle-cpu-jan2007(31541)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Oracle E-Business Suite and Applications 6.2.3 has unknown impact and attack vectors related to Oracle Exchange, aka APPS02.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0292">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:enterprise_manager:10.1.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:enterprise_manager:10.1.0.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0292</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:06.423-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017522" xml:lang="en">1017522</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22083" xml:lang="en">22083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" xml:lang="en">TA07-017A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31541" xml:lang="en">oracle-cpu-jan2007(31541)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple unspecified vulnerabilities in Oracle Enterprise Manager 10.1.0.5 have unknown impact and attack vectors related to Oracle Agent, aka (1) EM01 and (2) EM02.  NOTE: EM05 might be related to CVE-2007-0222.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0293">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:enterprise_manager:10.1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:enterprise_manager:10.2.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:enterprise_manager:10.1.0.5</vuln:product>
      <vuln:product>cpe:/a:oracle:enterprise_manager:10.2.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0293</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:06.483-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017522" xml:lang="en">1017522</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22083" xml:lang="en">22083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" xml:lang="en">TA07-017A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31541" xml:lang="en">oracle-cpu-jan2007(31541)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple unspecified vulnerabilities in Oracle Enterprise Manager 10.1.0.5 and 10.2.0.1 have unknown impact and attack vectors related to (1) Oracle Agent (EM03) and (2) EM04 and (3) EM05 in Enterprise Manager Console.  NOTE: EM05 might be related to CVE-2007-0222.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0294">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:enterprise_manager:10.2.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:enterprise_manager:10.2.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0294</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:06.530-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>1.7</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017522" xml:lang="en">1017522</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22083" xml:lang="en">22083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" xml:lang="en">TA07-017A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31541" xml:lang="en">oracle-cpu-jan2007(31541)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Oracle Enterprise Manager 10.2.0.1 has unknown impact and attack vectors related to Database Cloning &amp; Data Guard Management, aka EM06.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0295">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:enterpriseone:8.22.13"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:enterpriseone:8.47.11"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:peoplesoft_enterprise:8.22.13"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:peoplesoft_enterprise:8.47.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:enterpriseone:8.22.13</vuln:product>
      <vuln:product>cpe:/a:oracle:enterpriseone:8.47.11</vuln:product>
      <vuln:product>cpe:/a:oracle:peoplesoft_enterprise:8.22.13</vuln:product>
      <vuln:product>cpe:/a:oracle:peoplesoft_enterprise:8.47.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0295</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:06.577-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017522" xml:lang="en">1017522</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22083" xml:lang="en">22083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" xml:lang="en">TA07-017A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31541" xml:lang="en">oracle-cpu-jan2007(31541)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.22.13 and 8.47.11 has unknown impact and attack vectors in PeopleTools, aka PSE01.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0296">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:enterpriseone:8.22.13"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:enterpriseone:8.47.11"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:enterpriseone:8.48.06"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:peoplesoft_enterprise:8.22.13"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:peoplesoft_enterprise:8.47.11"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:peoplesoft_enterprise:8.48.06"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:enterpriseone:8.22.13</vuln:product>
      <vuln:product>cpe:/a:oracle:enterpriseone:8.47.11</vuln:product>
      <vuln:product>cpe:/a:oracle:enterpriseone:8.48.06</vuln:product>
      <vuln:product>cpe:/a:oracle:peoplesoft_enterprise:8.22.13</vuln:product>
      <vuln:product>cpe:/a:oracle:peoplesoft_enterprise:8.47.11</vuln:product>
      <vuln:product>cpe:/a:oracle:peoplesoft_enterprise:8.48.06</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0296</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:06.640-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017522" xml:lang="en">1017522</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22083" xml:lang="en">22083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" xml:lang="en">TA07-017A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31541" xml:lang="en">oracle-cpu-jan2007(31541)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.22.13, 8.47.11, and 8.48.06 has unknown impact and attack vectors in PeopleTools, aka PSE02.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0297">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:enterpriseone:8.47.11"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:enterpriseone:8.48.06"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:peoplesoft_enterprise:8.47.11"/>
        <cpe-lang:fact-ref name="cpe:/a:oracle:peoplesoft_enterprise:8.48.06"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:enterpriseone:8.47.11</vuln:product>
      <vuln:product>cpe:/a:oracle:enterpriseone:8.48.06</vuln:product>
      <vuln:product>cpe:/a:oracle:peoplesoft_enterprise:8.47.11</vuln:product>
      <vuln:product>cpe:/a:oracle:peoplesoft_enterprise:8.48.06</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0297</vuln:cve-id>
    <vuln:published-datetime>2007-01-16T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:06.703-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017522" xml:lang="en">1017522</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html" xml:lang="en">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22083" xml:lang="en">22083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" xml:lang="en">TA07-017A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31541" xml:lang="en">oracle-cpu-jan2007(31541)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.47.11 and 8.48.06 has unknown impact and attack vectors in PeopleTools, aka PSE03.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0298">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:dexxaboy:lunarpoll:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:dexxaboy:lunarpoll:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0298</vuln:cve-id>
    <vuln:published-datetime>2007-01-17T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:11.103-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://attrition.org/pipermail/vim/2007-January/001236.html" xml:lang="en">20070112 Source Verify of LunarPoll PollDir RFI</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2152" xml:lang="en">2152</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017510" xml:lang="en">1017510</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456697/100/0/threaded" xml:lang="en">20070112 LunarPoll (PollDir) Remote File Include Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22024" xml:lang="en">22024</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0177" xml:lang="en">ADV-2007-0177</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31472" xml:lang="en">lunarpoll-show-file-include(31472)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3117" xml:lang="en">3117</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in show.php in LunarPoll, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the PollDir parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0299">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0299</vuln:cve-id>
    <vuln:published-datetime>2007-01-17T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:12.737-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305214" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" xml:lang="en">APPLE-SA-2007-03-13</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-11-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-11-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/515792" xml:lang="en">VU#515792</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017751" xml:lang="en">1017751</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" xml:lang="en">TA07-072A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0930" xml:lang="en">ADV-2007-0930</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in the byte_swap_sbin function in bsd/ufs/ufs/ufs_byte_order.c in Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service (kernel panic) by mounting a crafted Unix File System (UFS) DMG image, which triggers an invalid pointer dereference.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0300">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:tlm_cms:tlm_cms:1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:tlm_cms:tlm_cms:1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0300</vuln:cve-id>
    <vuln:published-datetime>2007-01-17T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:58.067-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://attrition.org/pipermail/vim/2007-January/001238.html" xml:lang="en">20070112 [Bogus - partly] V TLM CMS &lt;= 1.1 (i-accueil.php chemin) Remote File Include Vulnerability (fwd)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22021" xml:lang="en">22021</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0176" xml:lang="en">ADV-2007-0176</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3118" xml:lang="en">3118</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in i-accueil.php in TLM CMS 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the chemin parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0301">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:fdweb:espace_membre:2.01"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:fdweb:espace_membre:2.01</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0301</vuln:cve-id>
    <vuln:published-datetime>2007-01-17T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:58.127-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22040" xml:lang="en">22040</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0178" xml:lang="en">ADV-2007-0178</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3123" xml:lang="en">3123</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in _admin/admin_menu.php in FdWeB Espace Membre 2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0302">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:instantasp:instantasp:4.1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:instantasp:instantasp:4.1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0302</vuln:cve-id>
    <vuln:published-datetime>2007-01-17T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:11.870-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2164" xml:lang="en">2164</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456970/100/0/threaded" xml:lang="en">20070115 InstantForum.NET Multiple Cross-Site Scripting Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22052" xml:lang="en">22052</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0227" xml:lang="en">ADV-2007-0227</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31521" xml:lang="en">instantforum-multiple-scripts-xss(31521)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in InstantASP 4.1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) SessionID parameter to (a) Logon.aspx, and the (2) Username and (3) Update parameters to (b) Members1.aspx.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0303">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:pancake.org:zina:1.0_rc1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:pancake.org:zina:1.0_rc1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0303</vuln:cve-id>
    <vuln:published-datetime>2007-01-17T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:13.127-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.pancake.org/zina-changelog-12" xml:lang="en">http://www.pancake.org/zina-changelog-12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22049" xml:lang="en">22049</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0181" xml:lang="en">ADV-2007-0181</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple unspecified vulnerabilities in Zina 1.0rc1 and earlier have unknown impact and attack vectors related to "Potential security bugs."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0304">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mint:haber_sistemi:2.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mint:haber_sistemi:2.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0304</vuln:cve-id>
    <vuln:published-datetime>2007-01-17T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:58.190-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0175" xml:lang="en">ADV-2007-0175</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3120" xml:lang="en">3120</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in duyuru.asp in MiNT Haber Sistemi 2.7 allows remote attackers to execute arbitrary SQL commands via the id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0305">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:okulsistem_okul_web:otomasyon_sistemi:4.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:okulsistem_okul_web:otomasyon_sistemi:4.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0305</vuln:cve-id>
    <vuln:published-datetime>2007-01-17T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:12.387-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2151" xml:lang="en">2151</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456894/100/0/threaded" xml:lang="en">20070115 Okul Web Otomasyon Sistemi (etkinlikbak.asp) SQL Injection Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22060" xml:lang="en">22060</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0206" xml:lang="en">ADV-2007-0206</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3135" xml:lang="en">3135</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in etkinlikbak.asp in Okul Web Otomasyon Sistemi 4.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0306">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:digiappz:digiaffiliate:1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:digiappz:digiaffiliate:1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0306</vuln:cve-id>
    <vuln:published-datetime>2007-01-17T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:58.317-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22039" xml:lang="en">22039</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0179" xml:lang="en">ADV-2007-0179</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3122" xml:lang="en">3122</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in visu_user.asp in Digiappz DigiAffiliate 1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0307">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:poplar_gedcom_viewer:poplar_gedcom_viewer:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:poplar_gedcom_viewer:poplar_gedcom_viewer:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:poplar_gedcom_viewer:poplar_gedcom_viewer:1.2.2</vuln:product>
      <vuln:product>cpe:/a:poplar_gedcom_viewer:poplar_gedcom_viewer:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0307</vuln:cve-id>
    <vuln:published-datetime>2007-01-17T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:58.377-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22038" xml:lang="en">22038</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0174" xml:lang="en">ADV-2007-0174</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3121" xml:lang="en">3121</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in include/common.php in Poplar Gedcom Viewer 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the env[rootPath] parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0308">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.7.4"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.7.5"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.7.6"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.8.2"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.8.3"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.8.4"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.8.5"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.8.6"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:7.2.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:plain_black:webgui:6.3.0</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.4.0</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.5.0</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.5.1</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.5.2</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.5.3</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.5.4</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.5.5</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.5.6</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.6.0</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.6.1</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.6.2</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.6.3</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.6.4</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.6.5</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.7.0</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.7.1</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.7.2</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.7.3</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.7.4</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.7.5</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.7.6</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.8.1</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.8.2</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.8.3</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.8.4</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.8.5</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.8.6</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:7.2.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0308</vuln:cve-id>
    <vuln:published-datetime>2007-01-17T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:39:49.140-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.plainblack.com/getwebgui/advisories/webgui-7_3_4-beta-released#BUeIjcWiQasypsJxD-YwgQ" xml:lang="en">http://www.plainblack.com/getwebgui/advisories/webgui-7_3_4-beta-released#BUeIjcWiQasypsJxD-YwgQ</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22051" xml:lang="en">22051</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Plain Black WebGUI before 7.3.4 (beta) allows remote attackers to inject arbitrary web script or HTML via Wiki Page titles.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0309">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:7.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:francisco_burzi:php-nuke:7.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0309</vuln:cve-id>
    <vuln:published-datetime>2007-01-17T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:12.870-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2153" xml:lang="en">2153</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017511" xml:lang="en">1017511</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.neosecurityteam.net/advisories/PHP-Nuke--7.9-Old-Articles-Block-cat-SQL-Injection-vulnerability-31.html" xml:lang="en">http://www.neosecurityteam.net/advisories/PHP-Nuke--7.9-Old-Articles-Block-cat-SQL-Injection-vulnerability-31.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456787/100/0/threaded" xml:lang="en">20070113 PHP-Nuke &lt;= 7.9 Old-Articles Block "cat" SQL Injection vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22037" xml:lang="en">22037</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31482" xml:lang="en">phpnuke-blockoldarticles-sql-injection(31482)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in blocks/block-Old_Articles.php in Francisco Burzi PHP-Nuke 7.9 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cat parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0310">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bmc:remedy_action_request_system:5.01.02_patch_1267"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bmc:remedy_action_request_system:5.01.02_patch_1267</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0310</vuln:cve-id>
    <vuln:published-datetime>2007-01-17T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:13.433-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2162" xml:lang="en">2162</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017515" xml:lang="en">1017515</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.alighieri.org/advisories/advisory-remedy50102.txt" xml:lang="en">http://www.alighieri.org/advisories/advisory-remedy50102.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456949/100/0/threaded" xml:lang="en">20070115 Remedy Action Request System 5.01.02 - User Enumeration</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457078/100/0/threaded" xml:lang="en">20070116 Re: Remedy Action Request System 5.01.02 - User Enumeration</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22066" xml:lang="en">22066</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0204" xml:lang="en">ADV-2007-0204</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31527" xml:lang="en">rars-login-information-disclosure(31527)</vuln:reference>
    </vuln:references>
    <vuln:summary>BMC Remedy Action Request System 5.01.02 Patch 1267 generates different error messages for failed login attempts with a valid username than for those with an invalid username, which allows remote attackers to determine valid account names.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0311">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:texas_imperial_software:wftpd:3.25"/>
        <cpe-lang:fact-ref name="cpe:/a:texas_imperial_software:wftpd_pro_server:3.25"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:texas_imperial_software:wftpd:3.25</vuln:product>
      <vuln:product>cpe:/a:texas_imperial_software:wftpd_pro_server:3.25</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0311</vuln:cve-id>
    <vuln:published-datetime>2007-01-17T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:58.440-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22046" xml:lang="en">22046</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31517" xml:lang="en">wftpd-admn-dos(31517)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3126" xml:lang="en">3126</vuln:reference>
    </vuln:references>
    <vuln:summary>Texas Imperial Software WFTPD and WFTPD Pro Server 3.25 and earlier allow remote attackers to cause a denial of service (application crash) via a long SITE ADMIN command.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0312">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:wcsimple_poll:wcsimple_poll"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wcsimple_poll:wcsimple_poll</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0312</vuln:cve-id>
    <vuln:published-datetime>2007-01-17T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:14.120-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2157" xml:lang="en">2157</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456982/100/0/threaded" xml:lang="en">20070114 wcSimple Poll (password.txt) Remote Password Disclosure Vulnerablity</vuln:reference>
    </vuln:references>
    <vuln:summary>wcSimple Poll stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain password hashes via a direct request for password.txt.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0313">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gonicus:gonicus_system_administration:2.5.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gonicus:gonicus_system_administration:2.5.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0313</vuln:cve-id>
    <vuln:published-datetime>2007-01-17T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:07.047-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://oss.gonicus.de/pipermail/gosa/2007-January/002650.html" xml:lang="en">[gosa] 20070115 GOsa 2.5.8 released (security fixes!)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0207" xml:lang="en">ADV-2007-0207</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31516" xml:lang="en">gosa-unspecified-data-manipulation(31516)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in GONICUS System Administration (GOsa) before 2.5.8 allows remote authenticated users to modify certain settings, including the admin password, via crafted POST requests.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0314">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:article_system:article_system:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:article_system:article_system:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0314</vuln:cve-id>
    <vuln:published-datetime>2007-01-17T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:58.503-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22017" xml:lang="en">22017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31446" xml:lang="en">article-system-includedir-file-include(31446)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3114" xml:lang="en">3114</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple PHP remote file inclusion vulnerabilities in Article System 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the INCLUDE_DIR parameter to (1) forms.php, (2) issue_edit.php, (3) client.php, and (4) classes.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0315">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:filezilla:filezilla:0.9.20"/>
        <cpe-lang:fact-ref name="cpe:/a:filezilla:filezilla:0.9.21"/>
        <cpe-lang:fact-ref name="cpe:/a:filezilla:filezilla:0.9.22"/>
        <cpe-lang:fact-ref name="cpe:/a:filezilla:filezilla:2.2.15"/>
        <cpe-lang:fact-ref name="cpe:/a:filezilla:filezilla:2.2.22"/>
        <cpe-lang:fact-ref name="cpe:/a:filezilla:filezilla:2.2.23"/>
        <cpe-lang:fact-ref name="cpe:/a:filezilla:filezilla:2.2.24"/>
        <cpe-lang:fact-ref name="cpe:/a:filezilla:filezilla:2.2.25"/>
        <cpe-lang:fact-ref name="cpe:/a:filezilla:filezilla:2.2.26"/>
        <cpe-lang:fact-ref name="cpe:/a:filezilla:filezilla:2.2.26a"/>
        <cpe-lang:fact-ref name="cpe:/a:filezilla:filezilla:2.2.27"/>
        <cpe-lang:fact-ref name="cpe:/a:filezilla:filezilla:2.2.28"/>
        <cpe-lang:fact-ref name="cpe:/a:filezilla:filezilla:2.2.29"/>
        <cpe-lang:fact-ref name="cpe:/a:filezilla:filezilla:2.2.30"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:filezilla:filezilla:0.9.20</vuln:product>
      <vuln:product>cpe:/a:filezilla:filezilla:0.9.21</vuln:product>
      <vuln:product>cpe:/a:filezilla:filezilla:0.9.22</vuln:product>
      <vuln:product>cpe:/a:filezilla:filezilla:2.2.15</vuln:product>
      <vuln:product>cpe:/a:filezilla:filezilla:2.2.22</vuln:product>
      <vuln:product>cpe:/a:filezilla:filezilla:2.2.23</vuln:product>
      <vuln:product>cpe:/a:filezilla:filezilla:2.2.24</vuln:product>
      <vuln:product>cpe:/a:filezilla:filezilla:2.2.25</vuln:product>
      <vuln:product>cpe:/a:filezilla:filezilla:2.2.26</vuln:product>
      <vuln:product>cpe:/a:filezilla:filezilla:2.2.26a</vuln:product>
      <vuln:product>cpe:/a:filezilla:filezilla:2.2.27</vuln:product>
      <vuln:product>cpe:/a:filezilla:filezilla:2.2.28</vuln:product>
      <vuln:product>cpe:/a:filezilla:filezilla:2.2.29</vuln:product>
      <vuln:product>cpe:/a:filezilla:filezilla:2.2.30</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0315</vuln:cve-id>
    <vuln:published-datetime>2007-01-17T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:07.173-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=475423&amp;group_id=21558" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=475423&amp;group_id=21558</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22057" xml:lang="en">22057</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0183" xml:lang="en">ADV-2007-0183</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31500" xml:lang="en">filezilla-options-queuectrl-bo(31500)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in FileZilla before 2.2.30a allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors related to (1) Options.cpp when storing settings in the registry, and (2) the transfer queue (QueueCtrl.cpp).  NOTE: some of these details are obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0316">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:all_in_one_control_panel:all_in_one_control_panel:1.3.010"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:all_in_one_control_panel:all_in_one_control_panel:1.3.010</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0316</vuln:cve-id>
    <vuln:published-datetime>2007-01-17T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:07.233-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2166" xml:lang="en">2166</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456741" xml:lang="en">20070112 AIOCP SQL Injection Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456742" xml:lang="en">20070112 AIOCP Login Bypass Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22032" xml:lang="en">22032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0190" xml:lang="en">ADV-2007-0190</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31485" xml:lang="en">aiocp-cpdownloads-sql-injection(31485)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in All In One Control Panel (AIOCP) 1.3.010 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) xuser_name parameter to shared/code/cp_authorization.php, and the (2) did parameter to public/code/cp_downloads.php, different vectors than CVE-2007-0223.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0317">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:filezilla:filezilla:3.0.0_beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:filezilla:filezilla:3.0.0_beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:filezilla:filezilla:3.0.0_beta4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:filezilla:filezilla:3.0.0_beta1</vuln:product>
      <vuln:product>cpe:/a:filezilla:filezilla:3.0.0_beta2</vuln:product>
      <vuln:product>cpe:/a:filezilla:filezilla:3.0.0_beta4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0317</vuln:cve-id>
    <vuln:published-datetime>2007-01-17T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:07.280-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=477793&amp;group_id=21558" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=477793&amp;group_id=21558</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22063" xml:lang="en">22063</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0182" xml:lang="en">ADV-2007-0182</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31497" xml:lang="en">filezilla-logmessage-format-string(31497)</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in the LogMessage function in FileZilla before 3.0.0-beta5 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted arguments.  NOTE: some of these details are obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0318">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0318</vuln:cve-id>
    <vuln:published-datetime>2007-01-17T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:15.097-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305214" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" xml:lang="en">APPLE-SA-2007-03-13</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-13-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-13-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017759" xml:lang="en">1017759</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" xml:lang="en">TA07-072A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0171" xml:lang="en">ADV-2007-0171</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0930" xml:lang="en">ADV-2007-0930</vuln:reference>
    </vuln:references>
    <vuln:summary>The do_hfs_truncate function in Mac OS X 10.4.8 allows context-dependent attackers to cause a denial of service (kernel panic) via a crafted HFS+ filesystem in a DMG image, which causes an access of an invalid vnode structure during file removal.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0319">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:motive_incorporated:self_service_manager:5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:motive_incorporated:service_activation_manager:5.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:motive_incorporated:self_service_manager:5.1</vuln:product>
      <vuln:product>cpe:/a:motive_incorporated:service_activation_manager:5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0319</vuln:cve-id>
    <vuln:published-datetime>2007-08-15T15:17:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:42:41.937-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1018571" xml:lang="en">1018571</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/747233" xml:lang="en">VU#747233</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.motive.com/securitybulletin_08122007.asp" xml:lang="en">http://www.motive.com/securitybulletin_08122007.asp</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/25312" xml:lang="en">25312</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2881" xml:lang="en">ADV-2007-2881</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-045" xml:lang="en">MS07-045</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/36034" xml:lang="en">activeutils-emaildata-bo(36034)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple stack-based buffer overflows in the Motive ActiveEmailTest.EmailData (ActiveUtils EmailData) ActiveX control in ActiveUtils.dll in Motive Service Activation Manager 5.1 and Self Service Manager 5.1 and earlier allow remote attackers to execute arbitrary code via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0320">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:macrovision:installfromtheweb"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:macrovision:installfromtheweb</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0320</vuln:cve-id>
    <vuln:published-datetime>2007-02-22T22:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:07.407-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/181041" xml:lang="en">VU#181041</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/MAPG-6UQUDP" xml:lang="en">http://www.kb.cert.org/vuls/id/MAPG-6UQUDP</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22672" xml:lang="en">22672</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0705" xml:lang="en">ADV-2007-0705</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32645" xml:lang="en">macrovision-installfromtheweb-activex-bo(32645)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in (a) an ActiveX control (iftw.dll) and (b) Netscape plug-in (npiftw32.dll) for Macrovision (formerly InstallShield) InstallFromTheWeb allow remote attackers to execute arbitrary code via crafted HTML documents.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0321">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:macrovision:flexnet_connect"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:macrovision:flexnet_connect</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0321</vuln:cve-id>
    <vuln:published-datetime>2007-02-22T22:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:07.453-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.installshield.com/kb/view.asp?articleid=Q113020" xml:lang="en">http://support.installshield.com/kb/view.asp?articleid=Q113020</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/847993" xml:lang="en">VU#847993</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/MAPG-6UERNR" xml:lang="en">http://www.kb.cert.org/vuls/id/MAPG-6UERNR</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0706" xml:lang="en">ADV-2007-0706</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32678" xml:lang="en">macrovision-updateservice-activex-bo(32678)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the Update Service Agent ActiveX Control in isusweb.dll for Macrovision FLEXnet Connect (formerly InstallShield Update Service) allows remote attackers to execute arbitrary code via the Download method.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0322">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:intuit:quickbooks:::online"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:intuit:quickbooks:::online</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0322</vuln:cve-id>
    <vuln:published-datetime>2007-09-05T15:17:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:07.500-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/907481" xml:lang="en">VU#907481</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/25544" xml:lang="en">25544</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/36462" xml:lang="en">quickbooks-activex-bo(36462)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple stack-based buffer overflows in the Intuit QuickBooks Online Edition ActiveX control before 10 allow remote attackers to execute arbitrary code via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0323">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:rim:teamon_import_object_activex_control"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rim:teamon_import_object_activex_control</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0323</vuln:cve-id>
    <vuln:published-datetime>2007-05-08T19:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:14.307-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.blackberry.com/btsc/articles/74/KB13142_f.SAL_Public.html" xml:lang="en">http://www.blackberry.com/btsc/articles/74/KB13142_f.SAL_Public.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/869641" xml:lang="en">VU#869641</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/468871/100/200/threaded" xml:lang="en">HPSBST02214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23331" xml:lang="en">23331</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" xml:lang="en">TA07-128A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1716" xml:lang="en">ADV-2007-1716</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-027" xml:lang="en">MS07-027</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/34182" xml:lang="en">rim-toimport-activex-bo(34182)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the SetLanguage function in Research In Motion (RIM) TeamOn Import Object ActiveX control (TOImport.dll) allows remote attackers to execute arbitrary code via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0324">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:lizardtech:djvu_browser_plug-in:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:lizardtech:djvu_browser_plug-in:6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:lizardtech:djvu_browser_plug-in:6.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:lizardtech:djvu_browser_plug-in:6.0</vuln:product>
      <vuln:product>cpe:/a:lizardtech:djvu_browser_plug-in:6.0.1</vuln:product>
      <vuln:product>cpe:/a:lizardtech:djvu_browser_plug-in:6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0324</vuln:cve-id>
    <vuln:published-datetime>2007-02-15T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:14.917-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2259" xml:lang="en">2259</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/522393" xml:lang="en">VU#522393</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.lizardtech.com/products/doc/djvupluginrelease.php" xml:lang="en">http://www.lizardtech.com/products/doc/djvupluginrelease.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460197/100/0/threaded" xml:lang="en">20070215 Lizardtech DjVu Browser Plug-in - Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22569" xml:lang="en">22569</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0618" xml:lang="en">ADV-2007-0618</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32510" xml:lang="en">djvu-browser-multiple-bo(32510)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in the LizardTech DjVu Browser Plug-in before 6.1.1 allow remote attackers to execute arbitrary code via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0325">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:client-server-messaging_security:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:officescan_corporate_edition:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:officescan_corporate_edition:7.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:trend_micro:client-server-messaging_security:3.0</vuln:product>
      <vuln:product>cpe:/a:trend_micro:officescan_corporate_edition:7.0</vuln:product>
      <vuln:product>cpe:/a:trend_micro:officescan_corporate_edition:7.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0325</vuln:cve-id>
    <vuln:published-datetime>2007-02-20T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:16.097-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034288" xml:lang="en">http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034288</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/784369" xml:lang="en">VU#784369</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22585" xml:lang="en">22585</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017664" xml:lang="en">1017664</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.trendmicro.com/ftp/documentation/readme/osce_70_win_en_securitypatch_1344_readme.txt" xml:lang="en">http://www.trendmicro.com/ftp/documentation/readme/osce_70_win_en_securitypatch_1344_readme.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0638" xml:lang="en">ADV-2007-0638</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in the Trend Micro OfficeScan Web-Deployment SetupINICtrl ActiveX control in OfficeScanSetupINI.dll, as used in OfficeScan 7.0 before Build 1344, OfficeScan 7.3 before Build 1241, and Client / Server / Messaging Security 3.0 before Build 1197, allow remote attackers to execute arbitrary code via a crafted HTML document.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0326">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:photochannel:pni_digital_media_upload_plugin_activex_control:2.0.0.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:photochannel:pni_digital_media_upload_plugin_activex_control:2.0.0.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0326</vuln:cve-id>
    <vuln:published-datetime>2007-09-18T16:17:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:07.673-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/854769" xml:lang="en">VU#854769</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/25685" xml:lang="en">25685</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018701" xml:lang="en">1018701</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/3181" xml:lang="en">ADV-2007-3181</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/36643" xml:lang="en">photochannel-photo-upload-bo(36643)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple stack-based buffer overflows in the PhotoChannel Networks PNI Digital Media Photo Upload Plugin ActiveX control before 2.0.0.10, as used by multiple retailers, allow remote attackers to execute arbitrary code via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0328">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:macrovision:flexnet_connect:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:macrovision:update_service:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:macrovision:update_service:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:macrovision:update_service:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:macrovision:flexnet_connect:6.0</vuln:product>
      <vuln:product>cpe:/a:macrovision:update_service:3.0</vuln:product>
      <vuln:product>cpe:/a:macrovision:update_service:4.0</vuln:product>
      <vuln:product>cpe:/a:macrovision:update_service:5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0328</vuln:cve-id>
    <vuln:published-datetime>2007-05-31T20:30:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:07.733-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.installshield.com/kb/view.asp?articleid=Q113020" xml:lang="en">http://support.installshield.com/kb/view.asp?articleid=Q113020</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.blackberry.com/btsc/articles/749/KB16469_f.SAL_Public.html" xml:lang="en">http://www.blackberry.com/btsc/articles/749/KB16469_f.SAL_Public.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/524681" xml:lang="en">VU#524681</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2017" xml:lang="en">ADV-2007-2017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/3278" xml:lang="en">ADV-2008-3278</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/34660" xml:lang="en">macrovision-dwupdate-command-execution(34660)</vuln:reference>
    </vuln:references>
    <vuln:summary>The DWUpdateService ActiveX control in the agent (agent.exe) in Macrovision FLEXnet Connect 6.0 and Update Service 3.x to 5.x allows remote attackers to execute arbitrary commands via (1) the Execute method, and obtain the exit status using (2) the GetExitCode method.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0329">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:joonas_viljanen:jv2_folder_gallery"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:joonas_viljanen:jv2_folder_gallery</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0329</vuln:cve-id>
    <vuln:published-datetime>2007-01-17T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:58.567-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0180" xml:lang="en">ADV-2007-0180</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3125" xml:lang="en">3125</vuln:reference>
    </vuln:references>
    <vuln:summary>download.php in Joonas Viljanen JV2 Folder Gallery allows remote attackers to read sensitive files via a relative pathname in the file parameter, as demonstrated by config/gallerysetup.php.  NOTE: this issue might be resultant from a directory traversal vulnerability.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0330">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ipswitch:ws_ftp_pro:2007"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ipswitch:ws_ftp_pro:2007</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0330</vuln:cve-id>
    <vuln:published-datetime>2007-01-17T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:15.620-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2160" xml:lang="en">2160</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456755/100/0/threaded" xml:lang="en">20070112 Ipswitch WS_FTP 2007 Professional "wsftpurl" access violation vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456901/100/0/threaded" xml:lang="en">20070114 Re: Ipswitch WS_FTP 2007 Professional "wsftpurl" access violation vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457097/100/0/threaded" xml:lang="en">20070116 Re: Ipswitch WS_FTP 2007 Professional "wsftpurl" access violation vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22062" xml:lang="en">22062</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in wsbho2k0.dll, as used by wsftpurl.exe, in Ipswitch WS_FTP 2007 Professional allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long ftp:// URL in an HTML document, and possibly other vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0331">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:xentraz:liens_dynamiques:2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xentraz:liens_dynamiques:2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0331</vuln:cve-id>
    <vuln:published-datetime>2007-01-17T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:16.183-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456986/100/0/threaded" xml:lang="en">20070114 liens_dynamiques xss and admin authentification</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22070" xml:lang="en">22070</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31528" xml:lang="en">liensdynamiques-liens-xss(31528)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in liens.php3 in liens_dynamiques 2.1 allows remote attackers to inject arbitrary web script or HTML by using the ajouter=1 query string and the add menu.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0332">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:xentraz:liens_dynamiques:2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xentraz:liens_dynamiques:2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0332</vuln:cve-id>
    <vuln:published-datetime>2007-01-17T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:16.463-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456986/100/0/threaded" xml:lang="en">20070114 liens_dynamiques xss and admin authentification</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22068" xml:lang="en">22068</vuln:reference>
    </vuln:references>
    <vuln:summary>(1) admin/adminlien.php3 and (2) admin/modif.php3 in liens_dynamiques 2.1 do not require authentication, which allows remote attackers to perform unauthorized administrative actions using a direct request.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0333">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:agnitum:outpost_firewall:4.0::pro"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:agnitum:outpost_firewall:4.0::pro</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0333</vuln:cve-id>
    <vuln:published-datetime>2007-01-17T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:16.697-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2163" xml:lang="en">2163</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.matousec.com/info/advisories/Outpost-Bypassing-Self-Protection-using-file-links.php" xml:lang="en">http://www.matousec.com/info/advisories/Outpost-Bypassing-Self-Protection-using-file-links.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456973/100/0/threaded" xml:lang="en">20070115 Outpost Bypassing Self-Protection using file links Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22069" xml:lang="en">22069</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31529" xml:lang="en">outpostfirewall-zwset-privilege-escalation(31529)</vuln:reference>
    </vuln:references>
    <vuln:summary>Agnitum Outpost Firewall PRO 4.0 allows local users to bypass access restrictions and insert Trojan horse drivers into the product's installation directory by creating links using FileLinkInformation requests with the ZwSetInformationFile function, as demonstrated by modifying SandBox.sys.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0334">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:ingate:firewall_and_siparator:4.5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:ingate:firewall_and_siparator:4.5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0334</vuln:cve-id>
    <vuln:published-datetime>2007-01-17T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:07.907-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.ingate.com/relnote-451.php" xml:lang="en">http://www.ingate.com/relnote-451.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22080" xml:lang="en">22080</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0209" xml:lang="en">ADV-2007-0209</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31546" xml:lang="en">ingate-sip-security-bypass(31546)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the SIP module in InGate Firewall and SIParator before 4.5.1 allows remote attackers to conduct replay attacks on the authentication mechanism via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0335">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:jax_scripts:jax_petition_book:1.0.3.06"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:jax_scripts:jax_petition_book:1.0.3.06</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0335</vuln:cve-id>
    <vuln:published-datetime>2007-01-17T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:17.120-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2161" xml:lang="en">2161</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456981/100/0/threaded" xml:lang="en">20070114 Jax Petition Book (languagepack) Remote File Include Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456989/100/0/threaded" xml:lang="en">20070115 Re: Jax Petition Book (languagepack) Remote File Include Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457077/100/0/threaded" xml:lang="en">20070116 Re: Jax Petition Book (languagepack) Remote File Include Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22072" xml:lang="en">22072</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0220" xml:lang="en">ADV-2007-0220</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31543" xml:lang="en">petitionbook-language-file-include(31543)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple directory traversal vulnerabilities in Jax Petition Book 1.0.3.06 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the languagepack parameter to (1) jax_petitionbook.php or (2) smileys.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0336">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:rixstep:undercover"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rixstep:undercover</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0336</vuln:cve-id>
    <vuln:published-datetime>2007-01-17T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:17:37.150-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.4</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-19T10:06:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051793.html" xml:lang="en">20070115 Rixstep aren't as leet as they thought they were</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22071" xml:lang="en">22071</vuln:reference>
    </vuln:references>
    <vuln:summary>Undercover.app/Contents/Resources/uc in Rixstep Undercover allows local users to overwrite arbitrary files, probably related to a race condition.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0337">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:kgb:kgb:1.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kgb:kgb:1.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0337</vuln:cve-id>
    <vuln:published-datetime>2007-01-17T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:58.627-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22065" xml:lang="en">22065</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0228" xml:lang="en">ADV-2007-0228</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31508" xml:lang="en">kgb-sesskglogadmin-file-include(31508)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3134" xml:lang="en">3134</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in sesskglogadmin.php in KGB 1.9 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the skinnn parameter, as demonstrated by invoking kg.php with a postek parameter containing PHP code, which is injected into a file in the kg directory, and then included by sesskglogadmin.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0338">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bolintech:dreamftp_server"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bolintech:dreamftp_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0338</vuln:cve-id>
    <vuln:published-datetime>2007-01-17T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:58.690-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3128" xml:lang="en">3128</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in Dream FTP Server allows remote attackers to execute arbitrary code via a USER command with a large number of format string specifiers, which triggers the overflow during processing of the Server Log.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0339">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:scriptme:sme_filemailer:1.21"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:scriptme:sme_filemailer:1.21</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0339</vuln:cve-id>
    <vuln:published-datetime>2007-01-17T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:17.917-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2154" xml:lang="en">2154</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-January/001244.html" xml:lang="en">20070117 Source VERIFY of SMe FileMailer 1.21 SQL injection</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457071/100/0/threaded" xml:lang="en">20070116 [x0n3-h4ck] SmE FileMailer 1.21 Remote Sql Injextion Exploit</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in index.php (aka the login form) in Scriptme SMe FileMailer 1.21 allows remote attackers to execute arbitrary SQL commands via the Password field (ps parameter).  NOTE: some of these details are obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0340">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:thwboard:thwboard:3.0_beta_2.84::php5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:thwboard:thwboard:3.0_beta_2.84::php5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0340</vuln:cve-id>
    <vuln:published-datetime>2007-01-17T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:58.737-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3124" xml:lang="en">3124</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in inc/header.inc.php in ThWboard 3.0b2.84-php5 and earlier allows remote attackers to execute arbitrary SQL commands via the board[styleid] parameter to index.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0341">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.8.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.8.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0341</vuln:cve-id>
    <vuln:published-datetime>2007-01-17T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:18.277-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456698/100/0/threaded" xml:lang="en">20070112 xss in phpmyadmin &lt;= 2.8.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456726/100/0/threaded" xml:lang="en">20070112 Re: xss in phpmyadmin &lt;= 2.8.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.virtuax.be/advisories/Advisory1-12012007.txt" xml:lang="en">http://www.virtuax.be/advisories/Advisory1-12012007.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.1 and earlier, when Microsoft Internet Explorer 6 is used, allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in a CSS style in the convcharset parameter to the top-level URI, a different vulnerability than CVE-2005-0992.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0342">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:2.0.4_419.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:webkit:build_18794"/>
        <cpe-lang:fact-ref name="cpe:/a:omnigroup:omniweb:5.5.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:safari:2.0.4_419.3</vuln:product>
      <vuln:product>cpe:/a:apple:webkit:build_18794</vuln:product>
      <vuln:product>cpe:/a:omnigroup:omniweb:5.5.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0342</vuln:cve-id>
    <vuln:published-datetime>2007-01-17T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-19T10:32:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://security-protocols.com/sp-x41-advisory.php" xml:lang="en">http://security-protocols.com/sp-x41-advisory.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22059" xml:lang="en">22059</vuln:reference>
    </vuln:references>
    <vuln:summary>WebCore in Apple WebKit build 18794 allows remote attackers to cause a denial of service (null dereference and application crash) via a TD element with a large number in the ROWSPAN attribute, as demonstrated by a crash of OmniWeb 5.5.3 on Mac OS X 10.4.8, a different vulnerability than CVE-2006-2019.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0343">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:openbsd:openbsd:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0343</vuln:cve-id>
    <vuln:published-datetime>2007-01-17T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:17:38.197-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-19T10:36:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017518" xml:lang="en">1017518</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OPENBSD</vuln:source>
      <vuln:reference href="http://www.openbsd.org/errata.html#icmp6" xml:lang="en">[4.0] 008: RELIABILITY FIX: January 16, 2007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OPENBSD</vuln:source>
      <vuln:reference href="http://www.openbsd.org/errata39.html#icmp6" xml:lang="en">[3.9] 018: RELIABILITY FIX: January 16, 2007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22087" xml:lang="en">22087</vuln:reference>
    </vuln:references>
    <vuln:summary>OpenBSD before 20070116 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via certain IPv6 ICMP (aka ICMP6) echo request packets.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0344">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:colloquy:colloquy:2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:colloquy:colloquy:2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0344</vuln:cve-id>
    <vuln:published-datetime>2007-01-17T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:58.787-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-134"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-16-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-16-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22086" xml:lang="en">22086</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0238" xml:lang="en">ADV-2007-0238</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3139" xml:lang="en">3139</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple format string vulnerabilities in (1) _invitedToRoom: and (2) _invitedToDirectChat: in Colloquy 2.1 and earlier allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in the channel name of an INVITE request, related to the implementation of AlertSheet and AlertPanel in Apple AppKit.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0345">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0345</vuln:cve-id>
    <vuln:published-datetime>2007-01-17T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:58.847-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-15-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-15-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31530" xml:lang="en">macosx-applications-privilege-escalation(31530)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3136" xml:lang="en">3136</vuln:reference>
    </vuln:references>
    <vuln:summary>The (1) Activity Monitor.app/Contents/Resources/pmTool, (2) Keychain Access.app/Contents/Resources/kcproxy, and (3) ODBC Administrator.app/Contents/Resources/iodbcadmintool programs in /Applications/Utilities/ in Mac OS X 10.4.8 have weak permissions (writable by admin group), which allows local admin users to gain root privileges by modifying a program and then performing permissions repair via diskutil.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0346">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sme:filemailer:1.21"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sme:filemailer:1.21</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0346</vuln:cve-id>
    <vuln:published-datetime>2007-01-17T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:08.110-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-January/001244.html" xml:lang="en">20070117 Source VERIFY of SMe FileMailer 1.21 SQL injection</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0221" xml:lang="en">ADV-2007-0221</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31533" xml:lang="en">smefilemailer-login-sql-injection(31533)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in index.php in SmE FileMailer 1.21 allows remote attackers to execute arbitrary SQL commands via the us parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0347">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cvstrac:cvstrac:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cvstrac:cvstrac:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cvstrac:cvstrac:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:cvstrac:cvstrac:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:cvstrac:cvstrac:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:cvstrac:cvstrac:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cvstrac:cvstrac:1.1</vuln:product>
      <vuln:product>cpe:/a:cvstrac:cvstrac:1.1.1</vuln:product>
      <vuln:product>cpe:/a:cvstrac:cvstrac:1.1.2</vuln:product>
      <vuln:product>cpe:/a:cvstrac:cvstrac:1.1.3</vuln:product>
      <vuln:product>cpe:/a:cvstrac:cvstrac:1.1.4</vuln:product>
      <vuln:product>cpe:/a:cvstrac:cvstrac:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0347</vuln:cve-id>
    <vuln:published-datetime>2007-01-29T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:18.603-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/052058.html" xml:lang="en">20070129 CVSTrac 2.0.0 Denial of Service (DoS) vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2192" xml:lang="en">2192</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.cvstrac.org/cvstrac/chngview?cn=850" xml:lang="en">http://www.cvstrac.org/cvstrac/chngview?cn=850</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.cvstrac.org/cvstrac/tktview?tn=683" xml:lang="en">http://www.cvstrac.org/cvstrac/tktview?tn=683</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>OPENPKG</vuln:source>
      <vuln:reference href="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.008.html" xml:lang="en">OpenPKG-SA-2007.008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458455/100/0/threaded" xml:lang="en">20070129 CVSTrac 2.0.0 Denial of Service (DoS) vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22296" xml:lang="en">22296</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0398" xml:lang="en">ADV-2007-0398</vuln:reference>
    </vuln:references>
    <vuln:summary>The is_eow function in format.c in CVSTrac before 2.0.1 does not properly check for the "'" (quote) character, which allows remote authenticated users to execute limited SQL injection attacks and cause a denial of service (database error) via a ' character in certain messages, tickets, or Wiki entries.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0348">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:interactual_technologies:interactual_player:2.60.12.0717"/>
        <cpe-lang:fact-ref name="cpe:/a:intervideo:windvd:7.0.27.172"/>
        <cpe-lang:fact-ref name="cpe:/a:roxio:cineplayer:3.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:interactual_technologies:interactual_player:2.60.12.0717</vuln:product>
      <vuln:product>cpe:/a:intervideo:windvd:7.0.27.172</vuln:product>
      <vuln:product>cpe:/a:roxio:cineplayer:3.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0348</vuln:cve-id>
    <vuln:published-datetime>2007-03-21T15:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:19.353-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/922969" xml:lang="en">VU#922969</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/463405/100/0/threaded" xml:lang="en">20070321 Secunia Research: InterActual Player / CinePlayer IASystemInfo.dllActiveX Control Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23071" xml:lang="en">23071</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1042" xml:lang="en">ADV-2007-1042</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1043" xml:lang="en">ADV-2007-1043</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33186" xml:lang="en">interactual-iasysteminfo-bo(33186)</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in the IASystemInfo.dll ActiveX control in (1) InterActual Player 2.60.12.0717, (2) Roxio CinePlayer 3.2, (3) WinDVD 7.0.27.172, and possibly other products, allows remote attackers to execute arbitrary code via a long ApplicationType property.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0349">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nicecoder:indexu:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nicecoder:indexu:5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0349</vuln:cve-id>
    <vuln:published-datetime>2007-01-18T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:20.183-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457079/100/0/threaded" xml:lang="en">20070116 vulnerability script indexu all versions</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31539" xml:lang="en">indexu-upgrade-file-include(31539)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in upgrade.php in nicecoder.com INDEXU 5.x allows remote attackers to include arbitrary local files via a .. (dot dot) in the gateway parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0350">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sme:filemailer:1.21"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sme:filemailer:1.21</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0350</vuln:cve-id>
    <vuln:published-datetime>2007-01-18T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:08.453-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2007-01/0395.html" xml:lang="en">20070116 [x0n3-h4ck] SmE FileMailer 1.21 Remote Sql Injextion Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://attrition.org/pipermail/vim/2007-January/001244.html" xml:lang="en">20070117 Source VERIFY of SMe FileMailer 1.21 SQL injection</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0221" xml:lang="en">ADV-2007-0221</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31533" xml:lang="en">smefilemailer-login-sql-injection(31533)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in (a) index.php and (b) dl.php in SmE FileMailer 1.21 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ps, (2) us, (3) f, or (4) code parameter.  NOTE: the us vector in index.php is already covered by CVE-2007-0346.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0351">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:tablet_pc"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:zonelabs:zonealarm"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:zonelabs:zonealarm</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0351</vuln:cve-id>
    <vuln:published-datetime>2007-01-18T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:20.463-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457167/100/0/threaded" xml:lang="en">20070117 Windows logoff bug possible security vulnerability and exploit.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457217/100/0/threaded" xml:lang="en">20070117 Re: Windows logoff bug possible security vulnerability and exploit.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457340/100/0/threaded" xml:lang="en">20070118 Re: Windows logoff bug possible security vulnerability and exploit.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457807/100/200/threaded" xml:lang="en">20070123 Re: Windows logoff bug possible security vulnerability and exploit.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459838/100/0/threaded" xml:lang="en">20070211 Windows logoff bug solution possibly.</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Windows XP and Windows Server 2003 do not properly handle user logoff, which might allow local users to gain the privileges of a previous system user, possibly related to user profile unload failure. NOTE: it is not clear whether this is an issue in Windows itself, or an interaction with another product.  The issue might involve ZoneAlarm not being able to terminate processes when it cannot prompt the user.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0352">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:html_help_workshop:4.02.0002"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:html_help_workshop:4.02.0002</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0352</vuln:cve-id>
    <vuln:published-datetime>2007-01-18T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:21.010-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2156" xml:lang="en">2156</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017530" xml:lang="en">1017530</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.anspi.pl/~porkythepig/visualization/cnt-expl1.cpp" xml:lang="en">http://www.anspi.pl/~porkythepig/visualization/cnt-expl1.cpp</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457210/100/0/threaded" xml:lang="en">20070117 Microsoft Help Workshop .CNT contents files buffer overflow vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22100" xml:lang="en">22100</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31555" xml:lang="en">ms-help-workshop-cnt-bo(31555)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3149" xml:lang="en">3149</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitrary code via a crafted .cnt file composed of lines that begin with an integer followed by a space and a long string.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0353">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mywebland:mybloggie:2.1.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mywebland:mybloggie:2.1.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0353</vuln:cve-id>
    <vuln:published-datetime>2007-01-18T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:21.620-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0338.html" xml:lang="en">20070117 [x0n3-h4ck] myBloggie 2.1.5 XSS exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://mywebland.com/forums/showtopic.php?t=1224" xml:lang="en">http://mywebland.com/forums/showtopic.php?t=1224</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2155" xml:lang="en">2155</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017531" xml:lang="en">1017531</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457206/100/0/threaded" xml:lang="en">20070117 [x0n3-h4ck] myBloggie 2.1.5 XSS exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22097" xml:lang="en">22097</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31554" xml:lang="en">mybloggie-indexlogin-xss(31554)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in (1) index.php and (2) login.php in myBloggie 2.1.5 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO string.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0354">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mgb:opensource_guestbook:0.5.4.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mgb:opensource_guestbook:0.5.4.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0354</vuln:cve-id>
    <vuln:published-datetime>2007-01-18T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:58.957-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-January/001246.html" xml:lang="en">20070118 vendor ACK for MGB Guestbook issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22094" xml:lang="en">22094</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.tv-kritik.net/mgb/index.php" xml:lang="en">http://www.tv-kritik.net/mgb/index.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0232" xml:lang="en">ADV-2007-0232</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31551" xml:lang="en">mgb-email-sql-injection(31551)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3141" xml:lang="en">3141</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in email.php in MGB OpenSource Guestbook 0.5.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0355">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:minimal_slp_service_agent:10.4.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:minimal_slp_service_agent:10.4.11</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0355</vuln:cve-id>
    <vuln:published-datetime>2007-01-18T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:59.020-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307430" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307430</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008/Feb/msg00002.html" xml:lang="en">APPLE-SA-2008-02-11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-17-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-17-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017533" xml:lang="en">1017533</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1019359" xml:lang="en">1019359</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22101" xml:lang="en">22101</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-043B.html" xml:lang="en">TA08-043B</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0239" xml:lang="en">ADV-2007-0239</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31562" xml:lang="en">macos-slpd-bo(31562)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3151" xml:lang="en">3151</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the Apple Minimal SLP v2 Service Agent (slpd) in Mac OS X 10.4.11 and earlier, including 10.4.8, allows local users, and possibly remote attackers, to gain privileges and possibly execute arbitrary code via a registration request with an invalid attr-list field.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0356">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:common_controls_replacement_project:foldertreeview_activex_control"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7.0::vista"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:common_controls_replacement_project:foldertreeview_activex_control</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:7.0::vista</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0356</vuln:cve-id>
    <vuln:published-datetime>2007-01-18T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:59.080-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22092" xml:lang="en">22092</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31549" xml:lang="en">ie-ccrp-dos(31549)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3142" xml:lang="en">3142</vuln:reference>
    </vuln:references>
    <vuln:summary>The Common Controls Replacement Project (CCRP) FolderTreeview (FTV) ActiveX control (ccrpftv6.ocx) allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long CCRP.RootFolder property value.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0357">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:fritzdsl:fritzdsl:02.02.29"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:fritzdsl:fritzdsl:02.02.29</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0357</vuln:cve-id>
    <vuln:published-datetime>2007-01-18T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:09.483-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051844.html" xml:lang="en">20070117 Flaw in AVM UPNP service for windows</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2159" xml:lang="en">2159</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22093" xml:lang="en">22093</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0236" xml:lang="en">ADV-2007-0236</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31556" xml:lang="en">fritz-avm-directory-traversal(31556)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in the AVM IGD CTRL Service in Fritz!DSL 02.02.29 allows remote attackers to read arbitrary files via ..%5C (URL-encoded dot dot backslash) sequences in a URI requested from the AR7 webserver.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0358">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:hp:jetdirect_firmware:x.20.nn"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:jetdirect_firmware:x.21.nn"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:jetdirect_firmware:x.22.nn"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:jetdirect_firmware:x.23.nn"/>
        <cpe-lang:fact-ref name="cpe:/h:hp:jetdirect_firmware:x.24.nn"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:hp:jetdirect_firmware:x.20.nn</vuln:product>
      <vuln:product>cpe:/h:hp:jetdirect_firmware:x.21.nn</vuln:product>
      <vuln:product>cpe:/h:hp:jetdirect_firmware:x.22.nn</vuln:product>
      <vuln:product>cpe:/h:hp:jetdirect_firmware:x.23.nn</vuln:product>
      <vuln:product>cpe:/h:hp:jetdirect_firmware:x.24.nn</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0358</vuln:cve-id>
    <vuln:published-datetime>2007-01-18T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:09.627-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://itrc.hp.com/service/cki/docDisplay.do?docId=c00838612" xml:lang="en">HPSBPI02185</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017532" xml:lang="en">1017532</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22105" xml:lang="en">22105</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0233" xml:lang="en">ADV-2007-0233</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31589" xml:lang="en">hp-jetdirect-unspecified-dos(31589)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the FTP server implementation in HP Jetdirect firmware x.20.nn through x.24.nn allows remote attackers to cause a denial of service via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0359">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:uberghey:cms:0.3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:uberghey:cms:0.3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0359</vuln:cve-id>
    <vuln:published-datetime>2007-01-18T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:59.127-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-January/001247.html" xml:lang="en">20070118 source verify: Uberghey CMS 0.3.1 RFI</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22098" xml:lang="en">22098</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0230" xml:lang="en">ADV-2007-0230</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31553" xml:lang="en">uberghey-frontpage-file-include(31553)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3147" xml:lang="en">3147</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in frontpage.php in Uberghey CMS 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the setup_folder parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0360">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oreon_project:oreon:1.2.3_rc4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oreon_project:oreon:1.2.3_rc4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0360</vuln:cve-id>
    <vuln:published-datetime>2007-01-18T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:22.230-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459811/100/0/threaded" xml:lang="en">20070211 Oreon1.2.x Series Exploit Coded</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22107" xml:lang="en">22107</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0229" xml:lang="en">ADV-2007-0229</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31568" xml:lang="en">oreon-index-file-include(31568)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3150" xml:lang="en">3150</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in lang/index.php in Oreon 1.2.3 RC4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0361">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:comscripts:phpmyphorum:1.5a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:comscripts:phpmyphorum:1.5a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0361</vuln:cve-id>
    <vuln:published-datetime>2007-01-18T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:59.253-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22099" xml:lang="en">22099</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0231" xml:lang="en">ADV-2007-0231</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31552" xml:lang="en">phpmyphorum-frame-file-include(31552)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3145" xml:lang="en">3145</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in mep/frame.php in PHPMyphorum 1.5a allows remote attackers to execute arbitrary PHP code via a URL in the chem parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0362">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:freshreader:freshreader"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:freshreader:freshreader</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0362</vuln:cve-id>
    <vuln:published-datetime>2007-01-18T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:09.860-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>JVN</vuln:source>
      <vuln:reference href="http://jvn.jp/jp/JVN%2395249468/index.html" xml:lang="en">JVN#95249468</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://manual.freshreader.com/archives/2007/01/20070118_javasc.html" xml:lang="en">http://manual.freshreader.com/archives/2007/01/20070118_javasc.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22106" xml:lang="en">22106</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0241" xml:lang="en">ADV-2007-0241</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31566" xml:lang="en">freshreader-rssfeed-xss(31566)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the RSS feed component in FreshReader before 1.0.07010600 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to tag attributes.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0363">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:openads:openads:2.0.8_pr1"/>
        <cpe-lang:fact-ref name="cpe:/a:openads:openads:2.0.8_pr1::postgresql"/>
        <cpe-lang:fact-ref name="cpe:/a:openads:openads:2.0.9_pr1"/>
        <cpe-lang:fact-ref name="cpe:/a:openads:openads:2.0.9_pr1::postgresql"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openads:openads:2.0.8_pr1</vuln:product>
      <vuln:product>cpe:/a:openads:openads:2.0.8_pr1::postgresql</vuln:product>
      <vuln:product>cpe:/a:openads:openads:2.0.9_pr1</vuln:product>
      <vuln:product>cpe:/a:openads:openads:2.0.9_pr1::postgresql</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0363</vuln:cve-id>
    <vuln:published-datetime>2007-01-18T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:09.923-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?group_id=11386&amp;release_id=479424" xml:lang="en">http://sourceforge.net/project/shownotes.php?group_id=11386&amp;release_id=479424</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?group_id=36679&amp;release_id=479426" xml:lang="en">http://sourceforge.net/project/shownotes.php?group_id=36679&amp;release_id=479426</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22124" xml:lang="en">22124</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0240" xml:lang="en">ADV-2007-0240</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31570" xml:lang="en">openads-unspecified-xss(31570)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in admin-search.php in (1) Openads for PostgreSQL (aka phpPgAds) before 2.0.10 and (2) Openads (aka phpAdsNew) before 2.0.10 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0364">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nicecoder:indexu:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:nicecoder:indexu:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:nicecoder:indexu:5.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nicecoder:indexu:5.0</vuln:product>
      <vuln:product>cpe:/a:nicecoder:indexu:5.0.1</vuln:product>
      <vuln:product>cpe:/a:nicecoder:indexu:5.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0364</vuln:cve-id>
    <vuln:published-datetime>2007-01-19T14:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:22.697-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457079/100/0/threaded" xml:lang="en">20070116 vulnerability script indexu all versions</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22084" xml:lang="en">22084</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0222" xml:lang="en">ADV-2007-0222</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31538" xml:lang="en">indexu-multiple-scripts-xss(31538)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in nicecoder.com INDEXU 5.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) error_msg parameter to (a) suggest_category.php; the (2) u parameter to (b) user_detail.php; the (3) friend_name, (4) friend_email, (5) error_msg, (6) my_name, (7) my_email, and (8) id parameters to (c) tell_friend.php; the (9) error_msg, (10) email, (11) name, and (12) subject parameters to (d) sendmail.php; the (13) email, (14) error_msg, and (15) username parameters to (e) send_pwd.php; the (16) keyword parameter to (f) search.php; the (17) error_msg, (18) username, (19) password, (20) password2, and (21) email parameters to (g) register.php; the (22) url, (23) contact_name, and (24) email parameters to (h) power_search.php; the (25) path and (26) total parameters to (i) new.php; the (27) query parameter to (j) modify.php; the (28) error_msg parameter to (k) login.php; the (29) error_msg and (30) email parameters to (l) mailing_list.php; the (31) gateway parameter to (m) upgrade.php; and another unspecified vector.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0365">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nicola_asuni:all_in_one_control_panel:1.3.000"/>
        <cpe-lang:fact-ref name="cpe:/a:nicola_asuni:all_in_one_control_panel:1.3.001"/>
        <cpe-lang:fact-ref name="cpe:/a:nicola_asuni:all_in_one_control_panel:1.3.002"/>
        <cpe-lang:fact-ref name="cpe:/a:nicola_asuni:all_in_one_control_panel:1.3.003"/>
        <cpe-lang:fact-ref name="cpe:/a:nicola_asuni:all_in_one_control_panel:1.3.004"/>
        <cpe-lang:fact-ref name="cpe:/a:nicola_asuni:all_in_one_control_panel:1.3.005"/>
        <cpe-lang:fact-ref name="cpe:/a:nicola_asuni:all_in_one_control_panel:1.3.006"/>
        <cpe-lang:fact-ref name="cpe:/a:nicola_asuni:all_in_one_control_panel:1.3.007"/>
        <cpe-lang:fact-ref name="cpe:/a:nicola_asuni:all_in_one_control_panel:1.3.008"/>
        <cpe-lang:fact-ref name="cpe:/a:nicola_asuni:all_in_one_control_panel:1.3.009"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nicola_asuni:all_in_one_control_panel:1.3.000</vuln:product>
      <vuln:product>cpe:/a:nicola_asuni:all_in_one_control_panel:1.3.001</vuln:product>
      <vuln:product>cpe:/a:nicola_asuni:all_in_one_control_panel:1.3.002</vuln:product>
      <vuln:product>cpe:/a:nicola_asuni:all_in_one_control_panel:1.3.003</vuln:product>
      <vuln:product>cpe:/a:nicola_asuni:all_in_one_control_panel:1.3.004</vuln:product>
      <vuln:product>cpe:/a:nicola_asuni:all_in_one_control_panel:1.3.005</vuln:product>
      <vuln:product>cpe:/a:nicola_asuni:all_in_one_control_panel:1.3.006</vuln:product>
      <vuln:product>cpe:/a:nicola_asuni:all_in_one_control_panel:1.3.007</vuln:product>
      <vuln:product>cpe:/a:nicola_asuni:all_in_one_control_panel:1.3.008</vuln:product>
      <vuln:product>cpe:/a:nicola_asuni:all_in_one_control_panel:1.3.009</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0365</vuln:cve-id>
    <vuln:published-datetime>2007-01-19T14:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:10.063-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=478370" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=478370</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0189" xml:lang="en">ADV-2007-0189</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31486" xml:lang="en">aiocp-unspecified-xss(31486)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in All In One Control Panel (AIOCP) 1.3.009 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: this is probably a different vulnerability than CVE-2006-5830.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0366">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:maxum_development_corporation:rumpus_ftp_server:5.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:maxum_development_corporation:rumpus_ftp_server:5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0366</vuln:cve-id>
    <vuln:published-datetime>2007-01-19T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:10.110-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-18-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-18-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31597" xml:lang="en">rumpus-path-privilege-escalation(31597)</vuln:reference>
    </vuln:references>
    <vuln:summary>Untrusted search path vulnerability in Rumpus 5.1 and earlier allows local users to gain privileges via a modified PATH that points to a malicious ipfw program.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0367">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:maxum_development_corporation:rumpus_ftp_server:5.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:maxum_development_corporation:rumpus_ftp_server:5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0367</vuln:cve-id>
    <vuln:published-datetime>2007-01-19T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:40:06.577-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-18-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-18-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Rumpus 5.1 and earlier has weak permissions for certain files and directories under /usr/local/Rumpus, including the configuration file, which allows local users to have an unknown impact by creating, modifying, or deleting files.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0368">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:michiel_broek:mbse-bbs:0.33.17"/>
        <cpe-lang:fact-ref name="cpe:/a:michiel_broek:mbse-bbs:0.33.18"/>
        <cpe-lang:fact-ref name="cpe:/a:michiel_broek:mbse-bbs:0.33.19"/>
        <cpe-lang:fact-ref name="cpe:/a:michiel_broek:mbse-bbs:0.33.20"/>
        <cpe-lang:fact-ref name="cpe:/a:michiel_broek:mbse-bbs:0.35.7"/>
        <cpe-lang:fact-ref name="cpe:/a:michiel_broek:mbse-bbs:0.36"/>
        <cpe-lang:fact-ref name="cpe:/a:michiel_broek:mbse-bbs:0.38"/>
        <cpe-lang:fact-ref name="cpe:/a:michiel_broek:mbse-bbs:0.60"/>
        <cpe-lang:fact-ref name="cpe:/a:michiel_broek:mbse-bbs:0.70"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:michiel_broek:mbse-bbs:0.33.17</vuln:product>
      <vuln:product>cpe:/a:michiel_broek:mbse-bbs:0.33.18</vuln:product>
      <vuln:product>cpe:/a:michiel_broek:mbse-bbs:0.33.19</vuln:product>
      <vuln:product>cpe:/a:michiel_broek:mbse-bbs:0.33.20</vuln:product>
      <vuln:product>cpe:/a:michiel_broek:mbse-bbs:0.35.7</vuln:product>
      <vuln:product>cpe:/a:michiel_broek:mbse-bbs:0.36</vuln:product>
      <vuln:product>cpe:/a:michiel_broek:mbse-bbs:0.38</vuln:product>
      <vuln:product>cpe:/a:michiel_broek:mbse-bbs:0.60</vuln:product>
      <vuln:product>cpe:/a:michiel_broek:mbse-bbs:0.70</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0368</vuln:cve-id>
    <vuln:published-datetime>2007-01-19T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:59.317-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051859.html" xml:lang="en">20070118 mbsebbs 0.70.0 &amp; below local root exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.mbse.eu/mbse/mbsebbs/index.html" xml:lang="en">http://www.mbse.eu/mbse/mbsebbs/index.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22112" xml:lang="en">22112</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31639" xml:lang="en">mbsebbs-mbuseradd-bo(31639)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3154" xml:lang="en">3154</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in mbse-bbs 0.70 and earlier allows local users to execute arbitrary code via a long string in the MBSE_ROOT environment variable.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0369">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpbp:phpbp:rc3_2.204"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpbp:phpbp:rc3_2.204</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0369</vuln:cve-id>
    <vuln:published-datetime>2007-01-19T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:59.363-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31622" xml:lang="en">phpbp-comment-sql-injection(31622)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3153" xml:lang="en">3153</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in phpBP RC3 (2.204) and earlier allows remote attackers to execute arbitrary SQL commands via the comment forum.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0370">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpbp:phpbp:rc3_2.204"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpbp:phpbp:rc3_2.204</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0370</vuln:cve-id>
    <vuln:published-datetime>2007-01-19T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:59.427-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31619" xml:lang="en">phpbp-banner-file-upload(31619)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3153" xml:lang="en">3153</vuln:reference>
    </vuln:references>
    <vuln:summary>Unrestricted file upload vulnerability in index.php in phpBP RC3 (2.204) and earlier allows remote administrators to inject arbitrary PHP code into an upload/banners/ file via a banners add operation that uploads the PHP code through an image_form parameter specifying a multiple-extension filename such as .jpg.vil.gif.php, which is stored in upload/banners/ under a different name, and executable via a direct request.  NOTE: a separate SQL injection issue could be leveraged to make this vulnerability reachable by remote unauthenticated attackers.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0371">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:common_controls_replacement_project:browsedialog_server"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:common_controls_replacement_project:browsedialog_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0371</vuln:cve-id>
    <vuln:published-datetime>2007-01-19T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:59.473-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22110" xml:lang="en">22110</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3155" xml:lang="en">3155</vuln:reference>
    </vuln:references>
    <vuln:summary>A certain ActiveX control in the Common Controls Replacement Project (CCRP) CCRP BrowseDialog Server (ccrpbds6.dll) allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long CCRP_BDc.SelectedFolder property value.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0372">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:7.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:francisco_burzi:php-nuke:7.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0372</vuln:cve-id>
    <vuln:published-datetime>2007-01-19T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:24.010-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" xml:lang="en">20070118 The vulnerabilities festival !</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.hackers.ir/advisories/festival.txt" xml:lang="en">http://www.hackers.ir/advisories/festival.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459174/100/0/threaded" xml:lang="en">20070204 Sql injection bugs in PHP-Nuke</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22116" xml:lang="en">22116</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in Francisco Burzi PHP-Nuke 7.9 allow remote attackers to execute arbitrary SQL commands via (1) the active parameter in admin/modules/modules.php; the (2) ad_class, (3) imageurl, (4) clickurl, (5) ad_code, or (6) position parameter in modules/Advertising/admin/index.php; or unspecified vectors in the (7) advertising, (8) weblinks, or (9) reviews section.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0373">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.5.0_beta"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:joomla:joomla:1.5.0_beta</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0373</vuln:cve-id>
    <vuln:published-datetime>2007-01-19T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:24.527-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" xml:lang="en">20070118 The vulnerabilities festival !</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.hackers.ir/advisories/festival.txt" xml:lang="en">http://www.hackers.ir/advisories/festival.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459203/100/0/threaded" xml:lang="en">20070204 Sql injection bugs in Joomla and Mambo</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22122" xml:lang="en">22122</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in Joomla! 1.5.0 Beta allow remote attackers to execute arbitrary SQL commands via (1) the searchword parameter in certain files; the where parameter in (2) plugins/search/content.php or (3) plugins/search/weblinks.php; the text parameter in (4) plugins/search/contacts.php, (5) plugins/search/categories.php, or (6) plugins/search/sections.php; or (7) the email parameter in database/table/user.php, which is not properly handled by the check function.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0374">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.5.0_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mambo:mambo:4.6.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:joomla:joomla:1.0.11</vuln:product>
      <vuln:product>cpe:/a:joomla:joomla:1.5.0_beta</vuln:product>
      <vuln:product>cpe:/a:mambo:mambo:4.6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0374</vuln:cve-id>
    <vuln:published-datetime>2007-01-19T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:25.277-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" xml:lang="en">20070118 The vulnerabilities festival !</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.hackers.ir/advisories/festival.txt" xml:lang="en">http://www.hackers.ir/advisories/festival.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459203/100/0/threaded" xml:lang="en">20070204 Sql injection bugs in Joomla and Mambo</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/19734" xml:lang="en">19734</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in (1) Joomla! 1.0.11 and 1.5 Beta, and (2) Mambo 4.6.1, allows remote attackers to execute arbitrary SQL commands via the id parameter when cancelling content editing.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0375">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:1.5.0_beta"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:joomla:joomla:1.5.0_beta</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0375</vuln:cve-id>
    <vuln:published-datetime>2007-01-19T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:25.603-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" xml:lang="en">20070118 The vulnerabilities festival !</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.hackers.ir/advisories/festival.txt" xml:lang="en">http://www.hackers.ir/advisories/festival.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459203/100/0/threaded" xml:lang="en">20070204 Sql injection bugs in Joomla and Mambo</vuln:reference>
    </vuln:references>
    <vuln:summary>Joomla! 1.5.0 Beta allows remote attackers to obtain sensitive information via a direct request for (1) plugins/user/example.php; (2) gmail.php, (3) example.php, or (4) ldap.php in plugins/authentication/; (5) modules/mod_mainmenu/menu.php; or other unspecified PHP scripts, which reveals the path in various error messages, related to a jimport function call at the beginning of each script.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0376">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:virtuemart:virtuemart:1.0.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:virtuemart:virtuemart:1.0.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0376</vuln:cve-id>
    <vuln:published-datetime>2007-01-19T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:26.073-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" xml:lang="en">20070118 The vulnerabilities festival !</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://virtuemart.svn.sourceforge.net/viewvc/*checkout*/virtuemart/branches/virtuemart-1_0_0/virtuemart/CHANGELOG.php?revision=607" xml:lang="en">http://virtuemart.svn.sourceforge.net/viewvc/*checkout*/virtuemart/branches/virtuemart-1_0_0/virtuemart/CHANGELOG.php?revision=607</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.hackers.ir/advisories/festival.txt" xml:lang="en">http://www.hackers.ir/advisories/festival.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459195/100/0/threaded" xml:lang="en">20070204 Sql injection bugs in Virtuemart and Letterman</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22123" xml:lang="en">22123</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Virtuemart 1.0.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0377">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:xoops:xoops:2.0.16"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xoops:xoops:2.0.16</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0377</vuln:cve-id>
    <vuln:published-datetime>2007-01-19T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:26.447-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" xml:lang="en">20070118 The vulnerabilities festival !</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.hackers.ir/advisories/festival.txt" xml:lang="en">http://www.hackers.ir/advisories/festival.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459150/100/0/threaded" xml:lang="en">20070204 Sql injection bugs in Xoops 2.0.16 + Weblinks module</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22399" xml:lang="en">22399</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in Xoops 2.0.16 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in kernel/group.php in core, (2) the lid parameter in class/table_broken.php in the Weblinks module, and other unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0378">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:docman:docman:1.3_rc2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:docman:docman:1.3_rc2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0378</vuln:cve-id>
    <vuln:published-datetime>2007-01-19T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-13T01:31:43.813-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" xml:lang="en">20070118 The vulnerabilities festival !</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.hackers.ir/advisories/festival.txt" xml:lang="en">http://www.hackers.ir/advisories/festival.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in DocMan 1.3 RC2 allow attackers to execute arbitrary SQL commands via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0379">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:docman:docman:1.3_rc2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:docman:docman:1.3_rc2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0379</vuln:cve-id>
    <vuln:published-datetime>2007-01-19T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-13T01:31:43.987-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" xml:lang="en">20070118 The vulnerabilities festival !</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.hackers.ir/advisories/festival.txt" xml:lang="en">http://www.hackers.ir/advisories/festival.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in DocMan 1.3 RC2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0380">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:docman:docman:1.3_rc2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:docman:docman:1.3_rc2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0380</vuln:cve-id>
    <vuln:published-datetime>2007-01-19T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-13T01:31:44.143-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" xml:lang="en">20070118 The vulnerabilities festival !</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.hackers.ir/advisories/festival.txt" xml:lang="en">http://www.hackers.ir/advisories/festival.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>DocMan 1.3 RC2 allows remote attackers to obtain sensitive information (the full path) via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0381">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:adaptive_technology_resource_centre:atutor:1.5.3.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adaptive_technology_resource_centre:atutor:1.5.3.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0381</vuln:cve-id>
    <vuln:published-datetime>2007-01-19T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-13T01:31:44.347-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" xml:lang="en">20070118 The vulnerabilities festival !</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.atutor.ca/atutor/mantis/changelog_page.php" xml:lang="en">http://www.atutor.ca/atutor/mantis/changelog_page.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.hackers.ir/advisories/festival.txt" xml:lang="en">http://www.hackers.ir/advisories/festival.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in ATutor 1.5.3.2 allow remote attackers to execute arbitrary SQL commands via unspecified parameters.  NOTE: CVE analysis suggests that the vendor fixed these issues.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0382">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:letterman:letterman:1.2.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:letterman:letterman:1.2.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0382</vuln:cve-id>
    <vuln:published-datetime>2007-01-19T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:26.777-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" xml:lang="en">20070118 The vulnerabilities festival !</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.hackers.ir/advisories/festival.txt" xml:lang="en">http://www.hackers.ir/advisories/festival.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459195/100/0/threaded" xml:lang="en">20070204 Sql injection bugs in Virtuemart and Letterman</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22117" xml:lang="en">22117</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in letterman.class.php in the Letterman 1.2.3 (com_letterman) component for Joomla! before 1.0.12 allow remote attackers to execute arbitrary SQL commands via the id parameter, related to the (1) lm_sendMail, (2) saveNewsletter, and (3) cancelNewsletter functions.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0383">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:wdaemon:wdaemon:7.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:wdaemon:wdaemon:9.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:wdaemon:wdaemon:9.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wdaemon:wdaemon:7.2.0</vuln:product>
      <vuln:product>cpe:/a:wdaemon:wdaemon:9.0.4</vuln:product>
      <vuln:product>cpe:/a:wdaemon:wdaemon:9.5.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0383</vuln:cve-id>
    <vuln:published-datetime>2007-01-19T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-13T01:31:44.720-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" xml:lang="en">20070118 The vulnerabilities festival !</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.hackers.ir/advisories/festival.txt" xml:lang="en">http://www.hackers.ir/advisories/festival.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>** DISPUTED **  WDaemon 9.5.4 allows remote attackers to access the /WorldClient.dll URI on TCP port 3000, which has unknown impact.  NOTE: The researcher reports that the vendor response was "this is not a security bug."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0384">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:postnuke_software_foundation:postnuke:0.764"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:postnuke_software_foundation:postnuke:0.764</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0384</vuln:cve-id>
    <vuln:published-datetime>2007-01-19T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-13T01:31:44.860-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" xml:lang="en">20070118 The vulnerabilities festival !</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://noc.postnuke.com/plugins/scmsvn/viewcvs.php/trunk/Historic/PostNuke7x/html/modules/?root=postnuke" xml:lang="en">http://noc.postnuke.com/plugins/scmsvn/viewcvs.php/trunk/Historic/PostNuke7x/html/modules/?root=postnuke</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.hackers.ir/advisories/festival.txt" xml:lang="en">http://www.hackers.ir/advisories/festival.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22119" xml:lang="en">22119</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in preview in the reviews section in PostNuke 0.764 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0385">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:postnuke_software_foundation:postnuke:0.764"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:postnuke_software_foundation:postnuke:0.764</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0385</vuln:cve-id>
    <vuln:published-datetime>2007-01-19T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-13T01:31:45.017-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" xml:lang="en">20070118 The vulnerabilities festival !</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://noc.postnuke.com/plugins/scmsvn/viewcvs.php/trunk/Historic/PostNuke7x/html/modules/?root=postnuke" xml:lang="en">http://noc.postnuke.com/plugins/scmsvn/viewcvs.php/trunk/Historic/PostNuke7x/html/modules/?root=postnuke</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://noc.postnuke.com/plugins/scmsvn/viewcvs.php/trunk/Historic/PostNuke7x/html/modules/FAQ/index.php?root=postnuke&amp;r1=20350&amp;r2=20911" xml:lang="en">http://noc.postnuke.com/plugins/scmsvn/viewcvs.php/trunk/Historic/PostNuke7x/html/modules/FAQ/index.php?root=postnuke&amp;r1=20350&amp;r2=20911</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.hackers.ir/advisories/festival.txt" xml:lang="en">http://www.hackers.ir/advisories/festival.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>The faq section in PostNuke 0.764 allows remote attackers to obtain sensitive information (the full path) via "unvalidated output" in FAQ/index.php, possibly involving an undefined id_cat variable.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0386">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:postnuke_software_foundation:postnuke:0.764"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:postnuke_software_foundation:postnuke:0.764</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0386</vuln:cve-id>
    <vuln:published-datetime>2007-01-19T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-13T01:31:45.190-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" xml:lang="en">20070118 The vulnerabilities festival !</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.hackers.ir/advisories/festival.txt" xml:lang="en">http://www.hackers.ir/advisories/festival.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the rating section in PostNuke 0.764 has unknown impact and attack vectors, related to "an interesting bug."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0387">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:joomla:joomla:2007-01-18"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:joomla:joomla:2007-01-18</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0387</vuln:cve-id>
    <vuln:published-datetime>2007-01-19T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:27.057-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" xml:lang="en">20070118 The vulnerabilities festival !</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.hackers.ir/advisories/festival.txt" xml:lang="en">http://www.hackers.ir/advisories/festival.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459203/100/0/threaded" xml:lang="en">20070204 Sql injection bugs in Joomla and Mambo</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in models/category.php in the Weblinks component for Joomla! SVN 20070118 (com_weblinks) allows remote attackers to execute arbitrary SQL commands via the catid parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0388">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:woltlab:burning_board:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:woltlab:burning_board:2.3.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:woltlab:burning_board:1.0.2</vuln:product>
      <vuln:product>cpe:/a:woltlab:burning_board:2.3.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0388</vuln:cve-id>
    <vuln:published-datetime>2007-01-19T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:59.537-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31550" xml:lang="en">wbb-search-sql-injection(31550)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3143" xml:lang="en">3143</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3144" xml:lang="en">3144</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in search.php in Woltlab Burning Board (wBB) 1.0.2 and earlier, and 2.3.6 and earlier in the 2.x series, allows remote attackers to execute arbitrary SQL commands via the boardids[1] and other boardids[] parameters.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0389">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:arsdigita:arsdigita_community_education_solution:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:arsdigita:arsdigita_community_system:3.4.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:arsdigita:arsdigita_community_education_solution:1.1</vuln:product>
      <vuln:product>cpe:/a:arsdigita:arsdigita_community_system:3.4.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0389</vuln:cve-id>
    <vuln:published-datetime>2007-01-19T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:27.307-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457318/100/0/threaded" xml:lang="en">20070118 Directory Traversal in ArsDigita Community System</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22121" xml:lang="en">22121</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0286" xml:lang="en">ADV-2007-0286</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31613" xml:lang="en">acs-url-directory-traversal(31613)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in ArsDigita Community System (ACS) 3.4.10 and earlier, and ArsDigita Community Education Solution (ACES) 1.1, allows remote attackers to read arbitrary files via .%252e/ (double-encoded dot dot slash) sequences in the URI.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0390">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sabros.us:sabros.us:1.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sabros.us:sabros.us:1.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0390</vuln:cve-id>
    <vuln:published-datetime>2007-01-19T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:27.650-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051868.html" xml:lang="en">20070118 [x0n3-h4ck] sabros.us 1.7 XSS Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2170" xml:lang="en">2170</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457331/100/0/threaded" xml:lang="en">20070118 [x0n3-h4ck] sabros.us 1.7 XSS Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22115" xml:lang="en">22115</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31600" xml:lang="en">sabros-index-xss(31600)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in index.php in sabros.us 1.7 allows remote attackers to inject arbitrary web script or HTML via the tag parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0391">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bitdefender:bitdefender_client:professional_plus_8.02"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bitdefender:bitdefender_client:professional_plus_8.02</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0391</vuln:cve-id>
    <vuln:published-datetime>2007-01-19T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:28.103-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051883.html" xml:lang="en">20070119 Layered Defense Research Advisory: BitDefender Client 8.02 Format String Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.bitdefender.com/KB325-en--Format-string-vulnerability.html" xml:lang="en">http://www.bitdefender.com/KB325-en--Format-string-vulnerability.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457414/100/0/threaded" xml:lang="en">20070119 Layered Defense Research Advisory: BitDefender Client 8.02 Format String Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22128" xml:lang="en">22128</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0253" xml:lang="en">ADV-2007-0253</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31608" xml:lang="en">bitdefender-scanjob-format-string(31608)</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in the log creation functionality of BitDefender Client Professional Plus 8.02 allows attackers to execute arbitrary code via certain scan job settings.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0392">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:5.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0392</vuln:cve-id>
    <vuln:published-datetime>2007-01-19T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:28.543-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457279/100/0/threaded" xml:lang="en">20070118 Multiple OS kernel insecure handling of stdio file descriptor</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457315/100/0/threaded" xml:lang="en">20070118 Re: Multiple OS kernel insecure handling of stdio file descriptor</vuln:reference>
    </vuln:references>
    <vuln:summary>IBM AIX 5.3 does not properly verify the status of file descriptors before setuid execution, which allows local users to gain privileges by closing file descriptor 0, 1, or 2 and then invoking a setuid program, a variant of CVE-2002-0572.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0393">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0393</vuln:cve-id>
    <vuln:published-datetime>2007-01-19T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:28.747-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457279/100/0/threaded" xml:lang="en">20070118 Multiple OS kernel insecure handling of stdio file descriptor</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457315/100/0/threaded" xml:lang="en">20070118 Re: Multiple OS kernel insecure handling of stdio file descriptor</vuln:reference>
    </vuln:references>
    <vuln:summary>Sun Solaris 9 does not properly verify the status of file descriptors before setuid execution, which allows local users to gain privileges by closing file descriptor 0, 1, or 2 and then invoking a setuid program, a variant of CVE-2002-0572.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0394">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux:11.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0394</vuln:cve-id>
    <vuln:published-datetime>2007-01-19T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:28.947-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457279/100/0/threaded" xml:lang="en">20070118 Multiple OS kernel insecure handling of stdio file descriptor</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457315/100/0/threaded" xml:lang="en">20070118 Re: Multiple OS kernel insecure handling of stdio file descriptor</vuln:reference>
    </vuln:references>
    <vuln:summary>HP HP-UX B11.11 does not properly verify the status of file descriptors before setuid execution, which allows local users to gain privileges by closing file descriptor 0, 1, or 2 and then invoking a setuid program, a variant of CVE-2002-0572.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0395">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:comvironment:comvironment:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:comvironment:comvironment:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0395</vuln:cve-id>
    <vuln:published-datetime>2007-01-19T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:59.597-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22108" xml:lang="en">22108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0266" xml:lang="en">ADV-2007-0266</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31564" xml:lang="en">comvironment-grabglobals-file-include(31564)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3152" xml:lang="en">3152</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in libraries/grab_globals.lib.php in ComVironment 4.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0396">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.23::ia64_64-bit"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux:11.23::ia64_64-bit</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0396</vuln:cve-id>
    <vuln:published-datetime>2007-01-19T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:36.440-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6104" name="oval:org.mitre.oval:def:6104"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00837319" xml:lang="en">SSRT061289</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017527" xml:lang="en">1017527</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22103" xml:lang="en">22103</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0234" xml:lang="en">ADV-2007-0234</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31565" xml:lang="en">hp-ipfilter-dos(31565)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in HP-UX B.11.23, when running IPFilter in combination with PHNE_34474, allows remote attackers to cause a denial of service (system crash) via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0397">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:cisco:security_monitoring_analysis_and_response_system:4.2.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cisco:adaptive_security_appliance_device_manager:5.2.53"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cisco:adaptive_security_appliance_device_manager:5.2.53</vuln:product>
      <vuln:product>cpe:/h:cisco:security_monitoring_analysis_and_response_system:4.2.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0397</vuln:cve-id>
    <vuln:published-datetime>2007-01-19T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:04.340-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017535" xml:lang="en">1017535</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017536" xml:lang="en">1017536</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/en/US/products/products_security_advisory09186a00807c517f.shtml" xml:lang="en">20070118 SSL/TLS Certificate and SSH Public Key Validation Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22111" xml:lang="en">22111</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0245" xml:lang="en">ADV-2007-0245</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31567" xml:lang="en">cisco-csmars-asdm-device-spoofing(31567)</vuln:reference>
    </vuln:references>
    <vuln:summary>The Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.3 and Adaptive Security Device Manager (ASDM) before 5.2(2.54) do not validate the SSL/TLS certificates or SSH public keys when connecting to devices, which allows remote attackers to spoof those devices to obtain sensitive information or generate incorrect information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0398">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:arnotic:a-forum"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:arnotic:a-forum</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0398</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:29.150-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-January/001249.html" xml:lang="en">20070122 a-forum xss - who? what? where?</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457503/100/0/threaded" xml:lang="en">20070119 a-forum xss</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31610" xml:lang="en">aforum-unspecified-xss(31610)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in forum.php3 in Arnaud Guyonne (aka Arnotic) a-forum allow remote attackers to inject arbitrary web script or HTML via the (1) Sujet or (2) Pseudo field.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0399">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:simple_machines:simple_machines_forum:1.1_rc3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:simple_machines:simple_machines_forum:1.1_rc3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0399</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:29.433-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://aria-security.com/forum/showthread.php?p=128" xml:lang="en">http://aria-security.com/forum/showthread.php?p=128</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2169" xml:lang="en">2169</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457508/100/0/threaded" xml:lang="en">20070120 SMF "index.php?action=pm" Cross Site-Scripting</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457627/100/0/threaded" xml:lang="en">20070121 Re: SMF "index.php?action=pm" Cross Site-Scripting</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457761/100/200/threaded" xml:lang="en">20070122 Re: Re: Re: SMF "index.php?action=pm" Cross Site-Scripting</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458194/100/100/threaded" xml:lang="en">20070126 Re: Re: Re: Re: SMF "index.php?action=pm" Cross Site-Scripting</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458904/100/0/threaded" xml:lang="en">20070202 Re: SMF "index.php?action=pm" Cross Site-Scripting</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22143" xml:lang="en">22143</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31612" xml:lang="en">smf-pm-xss(31612)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in index.php in Simple Machines Forum (SMF) 1.1 RC3 allow remote authenticated users to inject arbitrary web script or HTML via the (1) recipient or (2) BCC field when selecting send in a pm action.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0400">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:easebay_resources:login_manager:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:easebay_resources:login_manager:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0400</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:30.277-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2167" xml:lang="en">2167</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457505/100/0/threaded" xml:lang="en">20070120 Login Manager Multiple HTML Injections</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31614" xml:lang="en">loginmanager-memberlist-xss(31614)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in admin/memberlist.php in Easebay Resources Login Manager 3.0 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0401">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:easebay_resources:login_manager:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:easebay_resources:login_manager:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0401</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:30.527-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2167" xml:lang="en">2167</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457505/100/0/threaded" xml:lang="en">20070120 Login Manager Multiple HTML Injections</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in admin/memberlist.php in Easebay Resources Login Manager 3.0 allows remote attackers to execute arbitrary SQL commands via the init_row parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0402">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:easebay_resources:paypal_subscription_manager"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:easebay_resources:paypal_subscription_manager</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0402</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:30.683-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2168" xml:lang="en">2168</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457506/100/0/threaded" xml:lang="en">20070120 Paypal Subscription Manager Multiple HTML Injections</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31618" xml:lang="en">psm-editmember-xss(31618)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in admin/edit_member.php in Easebay Resources Paypal Subscription Manager allows remote attackers to inject arbitrary web script or HTML via the username parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0403">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:easebay_resources:paypal_subscription_manager"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:easebay_resources:paypal_subscription_manager</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0403</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:30.980-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2168" xml:lang="en">2168</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457506/100/0/threaded" xml:lang="en">20070120 Paypal Subscription Manager Multiple HTML Injections</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31616" xml:lang="en">psm-memberlist-sql-injection(31616)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in admin/memberlist.php in Easebay Resources Paypal Subscription Manager allows remote attackers to execute arbitrary SQL commands via the keyword parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0404">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:django_project:django:0.95"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:django_project:django:0.95</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0404</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:10.983-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://code.djangoproject.com/changeset/3592" xml:lang="en">http://code.djangoproject.com/changeset/3592</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22134" xml:lang="en">22134</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31627" xml:lang="en">django-po-code-execution(31627)</vuln:reference>
    </vuln:references>
    <vuln:summary>bin/compile-messages.py in Django 0.95 does not quote argument strings before invoking the msgfmt program through the os.system function, which allows attackers to execute arbitrary commands via shell metacharacters in a (1) .po or (2) .mo file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0405">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:django_project:django:0.95"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:django_project:django:0.95</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0405</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:11.030-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://code.djangoproject.com/changeset/3754" xml:lang="en">http://code.djangoproject.com/changeset/3754</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22138" xml:lang="en">22138</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31628" xml:lang="en">django-request-session-hijacking(31628)</vuln:reference>
    </vuln:references>
    <vuln:summary>The LazyUser class in the AuthenticationMiddleware for Django 0.95 does not properly cache the user name across requests, which allows remote authenticated users to gain the privileges of a different user.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0406">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gxine:gxine:0.5.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gxine:gxine:0.5.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0406</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:11.077-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?group_id=9655&amp;release_id=476891" xml:lang="en">http://sourceforge.net/project/shownotes.php?group_id=9655&amp;release_id=476891</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0259" xml:lang="en">ADV-2007-0259</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://xinehq.de/index.php/news?show_category_id=1" xml:lang="en">http://xinehq.de/index.php/news?show_category_id=1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31604" xml:lang="en">gxine-serversetup-serverclient-bo(31604)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in the (1) main function in (a) client.c, and the (2) server_setup and (3) server_client_connect functions in (b) server.c in gxine 0.5.9 and earlier allow local users to cause a denial of service (daemon crash) or gain privileges via a long HOME environment variable.  NOTE: some of these details are obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0407">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.7.4"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.7.5"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.7.6"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.8.2"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.8.3"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.8.4"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.8.5"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:6.8.6"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:7.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:7.3.4_beta"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:plain_black:webgui:6.3.0</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.4.0</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.5.0</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.5.1</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.5.2</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.5.3</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.5.4</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.5.5</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.5.6</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.6.0</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.6.1</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.6.2</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.6.3</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.6.4</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.6.5</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.7.0</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.7.1</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.7.2</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.7.3</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.7.4</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.7.5</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.7.6</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.8.1</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.8.2</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.8.3</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.8.4</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.8.5</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:6.8.6</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:7.2.3</vuln:product>
      <vuln:product>cpe:/a:plain_black:webgui:7.3.4_beta</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0407</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:11.157-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.plainblack.com/bugs/tracker/security-update-cross-site-scripting-vulnerability" xml:lang="en">http://www.plainblack.com/bugs/tracker/security-update-cross-site-scripting-vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.plainblack.com/downloads/builds/7.3.5-beta/WebGUI/docs/changelog/7.x.x.txt" xml:lang="en">http://www.plainblack.com/downloads/builds/7.3.5-beta/WebGUI/docs/changelog/7.x.x.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22114" xml:lang="en">22114</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0242" xml:lang="en">ADV-2007-0242</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31573" xml:lang="en">webgui-username-xss(31573)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Operation/User.pm in Plain Black WebGUI before 7.3.5 (beta) allows remote attackers to inject arbitrary web script or HTML via the username parameter during anonymous registration, a different vector than CVE-2007-0308.  NOTE: it is possible that a separate "WikiPage titles" issue was also fixed.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0408">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0408</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:42.407-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BEA</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/pub/advisory/202" xml:lang="en">BEA07-135.00</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017519" xml:lang="en">1017519</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22082" xml:lang="en">22082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0213" xml:lang="en">ADV-2007-0213</vuln:reference>
    </vuln:references>
    <vuln:summary>BEA Weblogic Server 8.1 through 8.1 SP4 does not properly validate client certificates when reusing cached connections, which allows remote attackers to obtain access via an untrusted X.509 certificate.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0409">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp6"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:9.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp6</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp4</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:9.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0409</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:42.517-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>1.5</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BEA</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/pub/advisory/203" xml:lang="en">BEA07-136.00</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017525" xml:lang="en">1017525</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22082" xml:lang="en">22082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0213" xml:lang="en">ADV-2007-0213</vuln:reference>
    </vuln:references>
    <vuln:summary>BEA WebLogic 7.0 through 7.0 SP6, 8.1 through 8.1 SP4, and 9.0 initial release does not encrypt passwords stored in the JDBCDataSourceFactory MBean Properties, which allows local administrative users to read the cleartext password.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0410">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp5"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp6"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp5"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:9.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp2</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp3</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp4</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp5</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp6</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp2</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp3</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp4</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp5</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:9.0</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:9.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0410</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-17T15:03:57.800-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2018-10-17T14:17:41.400-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BEA</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/pub/advisory/204" xml:lang="en">BEA07-137.00</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017525" xml:lang="en">1017525</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22082" xml:lang="en">22082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0213" xml:lang="en">ADV-2007-0213</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the thread management in BEA WebLogic 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, 9.0, and 9.1, when T3 authentication is used, allows remote attackers to cause a denial of service (thread and system hang) via unspecified "sequences of events."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0411">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp5"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:9.2:ga"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp5</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:9.0</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:9.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:9.2:ga</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0411</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:42.783-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BEA</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/pub/advisory/205" xml:lang="en">BEA07-138.00</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017525" xml:lang="en">1017525</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22082" xml:lang="en">22082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0213" xml:lang="en">ADV-2007-0213</vuln:reference>
    </vuln:references>
    <vuln:summary>BEA WebLogic Server 8.1 through 8.1 SP5, 9.0, 9.1, and 9.2 Gold, when WS-Security is used, does not properly validate certificates, which allows remote attackers to conduct a man-in-the-middle (MITM) attack.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0412">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp5"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp6"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp7"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp5"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp6"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp7"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp2</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp3</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp4</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp5</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp6</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp7</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp2</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp3</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp4</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp5</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp6</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp7</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp2</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp3</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp4</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0412</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-17T15:04:05.127-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2018-10-17T14:35:04.343-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BEA</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/pub/advisory/206" xml:lang="en">BEA07-139.00</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017525" xml:lang="en">1017525</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22082" xml:lang="en">22082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0213" xml:lang="en">ADV-2007-0213</vuln:reference>
    </vuln:references>
    <vuln:summary>BEA WebLogic Server 6.1 through 6.1 SP7, 7.0 through 7.0 SP7, and 8.1 through 8.1 SP5 allows remote attackers to read arbitrary files inside the class-path property via .ear or exploded .ear files that use the manifest class-path property to point to utility jar files.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0413">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0413</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:43.033-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.4</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BEA</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/pub/advisory/207" xml:lang="en">BEA07-140.00</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017525" xml:lang="en">1017525</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22082" xml:lang="en">22082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0213" xml:lang="en">ADV-2007-0213</vuln:reference>
    </vuln:references>
    <vuln:summary>BEA WebLogic Server 8.1 through 8.1 SP5 stores cleartext data in a backup of config.xml after offline editing, which allows local users to obtain sensitive information by reading this backup file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0414">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp7"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp6"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp5"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:9.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp7</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp6</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp5</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:9.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0414</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:43.157-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BEA</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/pub/advisory/208" xml:lang="en">BEA07-141.00</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017525" xml:lang="en">1017525</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22082" xml:lang="en">22082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0213" xml:lang="en">ADV-2007-0213</vuln:reference>
    </vuln:references>
    <vuln:summary>BEA WebLogic Server 6.1 through 6.1 SP7, 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, and 9.0 allows remote attackers to cause a denial of service (server hang) via certain requests that cause muxer threads to block when processing error pages.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0415">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0415</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:43.267-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BEA</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/pub/advisory/209" xml:lang="en">BEA07-142.00</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017525" xml:lang="en">1017525</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22082" xml:lang="en">22082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0213" xml:lang="en">ADV-2007-0213</vuln:reference>
    </vuln:references>
    <vuln:summary>BEA WebLogic Server 8.1 through 8.1 SP5 does not properly enforce access control after a dynamic update and dynamic redeployment of an application that is implemented through exploded jars, which allows attackers to bypass intended access restrictions.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0416">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:9.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:weblogic_server:9.0</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:9.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0416</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:43.393-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BEA</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/pub/advisory/210" xml:lang="en">BEA07-143.00</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017525" xml:lang="en">1017525</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22082" xml:lang="en">22082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0213" xml:lang="en">ADV-2007-0213</vuln:reference>
    </vuln:references>
    <vuln:summary>The WSEE runtime (WS-Security runtime) in BEA WebLogic Server 9.0 and 9.1 does not verify credentials when decrypting client messages, which allows remote attackers to bypass application security.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0417">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp7"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp5"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:9.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp7</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp5</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:9.0</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:9.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0417</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:43.517-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BEA</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/pub/advisory/211" xml:lang="en">BEA07-144.00</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017525" xml:lang="en">1017525</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22082" xml:lang="en">22082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0213" xml:lang="en">ADV-2007-0213</vuln:reference>
    </vuln:references>
    <vuln:summary>BEA WebLogic Server 7.0 through 7.0 SP7, 8.1 through 8.1 SP5, 9.0, and 9.1, when using the WebLogic Server 6.1 compatibility realm, allows attackers to execute certain EJB container persistence operations with an administrative identity.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0418">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp6"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp5"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:9.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp6</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp5</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:9.0</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:9.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0418</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:43.643-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BEA</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/pub/advisory/212" xml:lang="en">BEA07-145.00</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017525" xml:lang="en">1017525</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22082" xml:lang="en">22082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0213" xml:lang="en">ADV-2007-0213</vuln:reference>
    </vuln:references>
    <vuln:summary>BEA WebLogic Server 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, 9.0, and 9.1 does not enforce a security policy that declares permissions for EJB methods that have array parameters, which allows remote attackers to obtain unauthorized access to these methods.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0419">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:weblogic_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0419</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:43.783-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BEA</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/pub/advisory/213" xml:lang="en">BEA07-146.00</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017525" xml:lang="en">1017525</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22082" xml:lang="en">22082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0213" xml:lang="en">ADV-2007-0213</vuln:reference>
    </vuln:references>
    <vuln:summary>The BEA WebLogic Server proxy plug-in before June 2006 for the Apache HTTP Server does not properly handle protocol errors, which allows remote attackers to cause a denial of service (server outage).</vuln:summary>
  </entry>
  <entry id="CVE-2007-0420">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:9.2:ga"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:weblogic_server:9.0</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:9.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:9.2:ga</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0420</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:43.893-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BEA</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/pub/advisory/214" xml:lang="en">BEA07-147.00</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017525" xml:lang="en">1017525</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22082" xml:lang="en">22082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0213" xml:lang="en">ADV-2007-0213</vuln:reference>
    </vuln:references>
    <vuln:summary>BEA WebLogic Server 9.0, 9.1, and 9.2 Gold allows remote attackers to obtain sensitive information via malformed HTTP requests, which reveal data from previous requests.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0421">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp5"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp6"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:6.1:sp7"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp5"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp6"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:7.0:sp7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp2</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp3</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp4</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp5</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp6</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:6.1:sp7</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp2</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp3</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp4</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp5</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp6</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:7.0:sp7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0421</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-17T15:04:09.407-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2018-10-17T14:39:08.217-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BEA</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/pub/advisory/215" xml:lang="en">BEA07-148.00</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017525" xml:lang="en">1017525</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22082" xml:lang="en">22082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0213" xml:lang="en">ADV-2007-0213</vuln:reference>
    </vuln:references>
    <vuln:summary>BEA WebLogic Server 6.1 through 6.1 SP7, and 7.0 through 7.0 SP7 allows remote attackers to cause a denial of service (disk consumption) via requests containing malformed headers, which cause a large amount of data to be written to the server log.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0422">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:9.2:ga"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:weblogic_server:9.0</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:9.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:9.2:ga</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0422</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:44.127-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BEA</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/pub/advisory/217" xml:lang="en">BEA07-150.00</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017525" xml:lang="en">1017525</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22082" xml:lang="en">22082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0213" xml:lang="en">ADV-2007-0213</vuln:reference>
    </vuln:references>
    <vuln:summary>BEA WebLogic Server 9.0, 9.1, and 9.2 Gold, when running on Solaris 9, allows remote attackers to cause a denial of service (server inaccessibility) via manipulated socket connections.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0423">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:weblogic_portal:9.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:weblogic_portal:9.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0423</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:28.980-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.4</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BEA</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/pub/advisory/218" xml:lang="en">BEA07-151.00</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017521" xml:lang="en">1017521</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22082" xml:lang="en">22082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0213" xml:lang="en">ADV-2007-0213</vuln:reference>
    </vuln:references>
    <vuln:summary>BEA WebLogic Portal 9.2 does not properly handle when an administrator deletes entitlements for a role, which causes other role entitlements to be "inadvertently affected," which has an unknown impact.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0424">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:weblogic_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0424</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:44.393-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BEA</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/pub/advisory/219" xml:lang="en">BEA07-152.00</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017525" xml:lang="en">1017525</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22082" xml:lang="en">22082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0213" xml:lang="en">ADV-2007-0213</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the BEA WebLogic Server proxy plug-in for Netscape Enterprise Server before September 2006 for Netscape Enterprise Server allow remote attackers to cause a denial of service via certain requests that trigger errors that lead to a server being marked as unavailable, hosting web server failure, or CPU consumption.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0425">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bea:jrockit:1.4.2:r24.5"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:weblogic_server:8.1:sp5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:jrockit:1.4.2:r24.5</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1</vuln:product>
      <vuln:product>cpe:/a:bea:weblogic_server:8.1:sp5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0425</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:44.517-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BEA</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/pub/advisory/222" xml:lang="en">BEA07-155.00</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017525" xml:lang="en">1017525</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0213" xml:lang="en">ADV-2007-0213</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in BEA WebLogic Platform and Server 8.1 through 8.1 SP5, and JRockit 1.4.2 R4.5 and earlier, allows attackers to gain privileges via unspecified vectors, related to an "overflow condition," probably a buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0426">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oracle:weblogic_portal:9.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oracle:weblogic_portal:9.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0426</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:28.980-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BEA</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/pub/advisory/223" xml:lang="en">BEA07-156.00</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017521" xml:lang="en">1017521</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22082" xml:lang="en">22082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0213" xml:lang="en">ADV-2007-0213</vuln:reference>
    </vuln:references>
    <vuln:summary>BEA WebLogic Portal 9.2, when running in a WebLogic Server clustered environment using WebLogic Portal entitlements, does not properly propagate entitlement policy changes if the changes are made on a managed server while the Administrative Server is unavailable, which might allow attackers to bypass intended restrictions.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0427">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:html_help_workshop:4.03.0002"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:html_help_workshop:4.03.0002</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0427</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:31.340-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2177" xml:lang="en">2177</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.anspi.pl/~porkythepig/visualization/hpj-x01.cpp" xml:lang="en">http://www.anspi.pl/~porkythepig/visualization/hpj-x01.cpp</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457436/100/0/threaded" xml:lang="en">20070119 Help project files (.HPJ) buffer overflow vulnerability in Microsoft Help Workshop</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22135" xml:lang="en">22135</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitrary code via a help project (.HPJ) file with a long HLP field in the OPTIONS section.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0428">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:wzdftpd:wzdftpd:8.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wzdftpd:wzdftpd:8.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0428</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:31.697-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051896.html" xml:lang="en">20070119 WzdFTPD &lt; 8.1 Denial of service</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2171" xml:lang="en">2171</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017537" xml:lang="en">1017537</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.s21sec.com/avisos/s21sec-033-en.txt" xml:lang="en">http://www.s21sec.com/avisos/s21sec-033-en.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457454/100/0/threaded" xml:lang="en">20070119 WzdFTPD &lt; 8.1 Denial of service</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0277" xml:lang="en">ADV-2007-0277</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31599" xml:lang="en">wzdftpd-ftp-dos(31599)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the chtbl_lookup function in hash.c for WzdFTPD 8.0 and earlier allows remote attackers to cause a denial of service via a crafted FTP command, probably due to a NULL pointer dereference.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0429">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:divx:divx_player:6.4.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:divx:divx_player:6.4.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0429</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:59.660-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22133" xml:lang="en">22133</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31601" xml:lang="en">divx-divxbrowserplugin-dos(31601)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3157" xml:lang="en">3157</vuln:reference>
    </vuln:references>
    <vuln:summary>DivXBrowserPlugin (aka DivX Web Player) npdivx32.dll, as distributed with DivX Player 6.4.1, allows remote attackers to cause a denial of service (Internet Explorer 7 crash) by invoking the GoWindowed method for a certain instance of the ActiveX object.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0430">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0430</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:32.293-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://risesecurity.org/advisory.php?id=RISE-2007001.txt" xml:lang="en">http://risesecurity.org/advisory.php?id=RISE-2007001.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2178" xml:lang="en">2178</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017538" xml:lang="en">1017538</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457466/100/0/threaded" xml:lang="en">20070119 [RISE-2007001] Apple Mac OS X 10.4.x kernel shared_region_map_file_np() memory corruption vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0275" xml:lang="en">ADV-2007-0275</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31645" xml:lang="en">macos-sharedregionmapfilenp-dos(31645)</vuln:reference>
    </vuln:references>
    <vuln:summary>The shared_region_map_file_np function in Apple Mac OS X 10.4.8 and earlier kernel allows local users to cause a denial of service (memory corruption) via a large mappingCount value.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0431">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:avm:fritzbox:7050"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:avm:fritzbox:7050</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0431</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:32.793-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="ftp://ftp.avm.de/fritz.box/fritzbox.fon_wlan_7050/firmware/info.txt" xml:lang="en">ftp://ftp.avm.de/fritz.box/fritzbox.fon_wlan_7050/firmware/info.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0387.html" xml:lang="en">20070119 DoS against AVM Fritz!Box 7050 (and others)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://mazzoo.de/blog/2007/01/18#FritzBox_DoS" xml:lang="en">http://mazzoo.de/blog/2007/01/18#FritzBox_DoS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457406/100/0/threaded" xml:lang="en">20070119 DoS against AVM Fritz!Box 7050 (and others)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457829/100/0/threaded" xml:lang="en">20070123 Re: DoS against AVM Fritz!Box 7050 (and others)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22130" xml:lang="en">22130</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0272" xml:lang="en">ADV-2007-0272</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31633" xml:lang="en">fritzbox-udp-packet-dos(31633)</vuln:reference>
    </vuln:references>
    <vuln:summary>AVM Fritz!Box 7050, and possibly other product models, allows remote attackers to cause a denial of service (VoIP application crash) via a zero-length UDP packet to the SIP port (port 5060).</vuln:summary>
  </entry>
  <entry id="CVE-2007-0432">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bea:aqualogic_service_bus:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:aqualogic_service_bus:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:aqualogic_service_bus:2.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:aqualogic_service_bus:2.0</vuln:product>
      <vuln:product>cpe:/a:bea:aqualogic_service_bus:2.1</vuln:product>
      <vuln:product>cpe:/a:bea:aqualogic_service_bus:2.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0432</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-13T01:31:53.487-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BEA</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/pub/advisory/224" xml:lang="en">BEA07-157.00</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017523" xml:lang="en">1017523</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22082" xml:lang="en">22082</vuln:reference>
    </vuln:references>
    <vuln:summary>BEA AquaLogic Service Bus 2.0, 2.1, and 2.5 does not properly reject malformed request messages to a proxy service, which might allow remote attackers to bypass authorization policies and route requests to back-end services or conduct other unauthorized activities.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0433">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bea:aqualogic_service_bus:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:aqualogic_service_bus:2.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:aqualogic_service_bus:2.0:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:aqualogic_service_bus:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:aqualogic_service_bus:2.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:aqualogic_service_bus:2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:aqualogic_service_bus:2.0</vuln:product>
      <vuln:product>cpe:/a:bea:aqualogic_service_bus:2.0:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:aqualogic_service_bus:2.0:sp2</vuln:product>
      <vuln:product>cpe:/a:bea:aqualogic_service_bus:2.1</vuln:product>
      <vuln:product>cpe:/a:bea:aqualogic_service_bus:2.1:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:aqualogic_service_bus:2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0433</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-13T01:31:53.673-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BEA</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/pub/advisory/221" xml:lang="en">BEA07-154.00</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017524" xml:lang="en">1017524</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22082" xml:lang="en">22082</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in BEA AquaLogic Enterprise Security 2.0 through 2.0 SP2, 2.1 through 2.1 SP1, and 2.2, when using Active Directory LDAP for authentication, allows remote authenticated users to access the server even after the account has been disabled.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0434">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bea:aqualogic_enterprise_security:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:aqualogic_enterprise_security:2.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:aqualogic_enterprise_security:2.0:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:aqualogic_enterprise_security:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:aqualogic_enterprise_security:2.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:bea:aqualogic_enterprise_security:2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bea:aqualogic_enterprise_security:2.0</vuln:product>
      <vuln:product>cpe:/a:bea:aqualogic_enterprise_security:2.0:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:aqualogic_enterprise_security:2.0:sp2</vuln:product>
      <vuln:product>cpe:/a:bea:aqualogic_enterprise_security:2.1</vuln:product>
      <vuln:product>cpe:/a:bea:aqualogic_enterprise_security:2.1:sp1</vuln:product>
      <vuln:product>cpe:/a:bea:aqualogic_enterprise_security:2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0434</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-13T01:31:53.860-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BEA</vuln:source>
      <vuln:reference href="http://dev2dev.bea.com/pub/advisory/220" xml:lang="en">BEA07-153.00</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22082" xml:lang="en">22082</vuln:reference>
    </vuln:references>
    <vuln:summary>BEA AquaLogic Enterprise Security 2.0 through 2.0 SP2, 2.1 through 2.1 SP1, and 2.2 does not properly set the severity level of audit events when the system load is high, which might make it easier for attackers to avoid detection.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0435">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/h:t-com:speedport_500v:-"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:t-com:speedport_500v_firmware:1.31"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:t-com:speedport_500v:-</vuln:product>
      <vuln:product>cpe:/o:t-com:speedport_500v_firmware:1.31</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0435</vuln:cve-id>
    <vuln:published-datetime>2007-01-22T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:35.247-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457453/100/0/threaded" xml:lang="en">20070119 Virginity Security Advisory 2007-001 : T-Com Speedport 500V Login bypass</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457645/100/0/threaded" xml:lang="en">20070121 Re: Virginity Security Advisory 2007-001 : T-Com Speedport 500V Login bypass</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457656/100/0/threaded" xml:lang="en">20070122 Re: Virginity Security Advisory 2007-001 : T-Com Speedport 500V Login bypass</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460319/100/0/threaded" xml:lang="en">20070216 Re: Virginity Security Advisory 2007-001 : T-Com Speedport 500V Login bypass</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22160" xml:lang="en">22160</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31621" xml:lang="en">tcom-login-authentication-bypass(31621)</vuln:reference>
    </vuln:references>
    <vuln:summary>T-Com Speedport 500V routers with firmware 1.31 allow remote attackers to bypass authentication and reconfigure the device via a LOGINKEY=TECOM cookie value.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0436">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:barron_mccann:install:bms1472"/>
        <cpe-lang:fact-ref name="cpe:/a:barron_mccann:x-kryptor_driver:bms1446hrr"/>
        <cpe-lang:fact-ref name="cpe:/a:barron_mccann:x-kryptor_secure_client"/>
        <cpe-lang:fact-ref name="cpe:/a:barron_mccann:xgntr:bms1351"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:barron_mccann:install:bms1472</vuln:product>
      <vuln:product>cpe:/a:barron_mccann:x-kryptor_driver:bms1446hrr</vuln:product>
      <vuln:product>cpe:/a:barron_mccann:x-kryptor_secure_client</vuln:product>
      <vuln:product>cpe:/a:barron_mccann:xgntr:bms1351</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0436</vuln:cve-id>
    <vuln:published-datetime>2007-02-03T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-05-18T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-02-05T23:08:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://jvn.jp/niscc/NISCC-462660/index.html" xml:lang="en">http://jvn.jp/niscc/NISCC-462660/index.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.barronmccann.com/ISec/s2pressrelease.asp?PRID=141&amp;S2ID=14" xml:lang="en">http://www.barronmccann.com/ISec/s2pressrelease.asp?PRID=141&amp;S2ID=14</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.bemacpromotions.com/files/xkpatch462660.zip" xml:lang="en">http://www.bemacpromotions.com/files/xkpatch462660.zip</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.cpni.gov.uk/Products/advisories/default.aspx?id=al-20070129-0107.xml" xml:lang="en">http://www.cpni.gov.uk/Products/advisories/default.aspx?id=al-20070129-0107.xml</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.cpni.gov.uk/Products/vulnerabilitydisclosures/default.aspx?id=va-20070129-0107.xml" xml:lang="en">http://www.cpni.gov.uk/Products/vulnerabilitydisclosures/default.aspx?id=va-20070129-0107.xml</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22424" xml:lang="en">22424</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0496" xml:lang="en">ADV-2007-0496</vuln:reference>
    </vuln:references>
    <vuln:summary>Barron McCann X-Kryptor Driver BMS1446HRR (Xgntr BMS1351 Install BMS1472) in X-Kryptor Secure Client does not drop privileges when launching an Explorer window in response to a help command, which allows local users to gain LocalSystem privileges via interactive use of Explorer.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0437">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:intersystems:cache_database"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:intersystems:cache_database</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0437</vuln:cve-id>
    <vuln:published-datetime>2007-08-20T14:17:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:17:52.757-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-08-20T14:22:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.cpni.gov.uk/Products/alerts/2928.aspx" xml:lang="en">http://www.cpni.gov.uk/Products/alerts/2928.aspx</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.mwrinfosecurity.com/advisories/mwri_cache-sample-files-xss-advisory_2007-04-04.pdf" xml:lang="en">http://www.mwrinfosecurity.com/advisories/mwri_cache-sample-files-xss-advisory_2007-04-04.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.mwrinfosecurity.com/news/1658.html" xml:lang="en">http://www.mwrinfosecurity.com/news/1658.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in the sample Cache' Server Page (CSP) scripts in InterSystems Cache' allow remote attackers to inject arbitrary web script or HTML via (1) the TO parameter to loop.csp, (2) the VALUE parameter to cookie.csp, and (3) the PAGE parameter to showsource.csp in csp/samples/; and allow remote authenticated users to inject arbitrary web script or HTML via (4) the ERROR parameter to csp/samples/xmlclasseserror.csp, and unspecified vectors in (5) object.csp and (6) lotteryhistory.csp in csp/samples/.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0441">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.20"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:6.41"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:7.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_network_node_manager:7.50"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.20</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:6.41</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:7.0.1</vuln:product>
      <vuln:product>cpe:/a:hp:openview_network_node_manager:7.50</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0441</vuln:cve-id>
    <vuln:published-datetime>2007-01-23T11:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:35.933-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017504" xml:lang="en">1017504</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/456623/100/100/threaded" xml:lang="en">SSRT05103</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0153" xml:lang="en">ADV-2007-0153</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 6.20, 6.4x, 7.01, and 7.50 allows remote attackers to execute arbitrary commands via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0442">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:ibm:os_400:r530"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:os_400:r535"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:os_400:r530</vuln:product>
      <vuln:product>cpe:/o:ibm:os_400:r535</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0442</vuln:cve-id>
    <vuln:published-datetime>2007-01-23T11:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:40:25.500-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?uid=nas204b3e62c8a63af708625718e0043eddc" xml:lang="en">MA33861</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?uid=nas2c8623b2ed01d45d08625718e0043edc2" xml:lang="en">MA33860</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in IBM OS/400 R530 and R535 has unknown impact and remote attack vectors, related to an "Integrity Problem" involving LIC-TCPIP and TCP reset.  NOTE: it is possible that this issue is related to CVE-2004-0230, but this is not certain.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0443">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gracenote:cddbcontrol_activex_control"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gracenote:cddbcontrol_activex_control</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0443</vuln:cve-id>
    <vuln:published-datetime>2007-04-24T12:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:36.197-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.gracenote.com/corporate/FAQs.html/faqset=update/page=0" xml:lang="en">http://www.gracenote.com/corporate/FAQs.html/faqset=update/page=0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/466403/100/0/threaded" xml:lang="en">20070420 ZDI-07-021: GraceNote CDDBControl ActiveX Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23567" xml:lang="en">23567</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017937" xml:lang="en">1017937</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1475" xml:lang="en">ADV-2007-1475</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-07-021.html" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-07-021.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33773" xml:lang="en">cddbcontrol-activex-bo(33773)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in the CDDBControl ActiveX control in Gracenote CDDB before 20070418 allow remote attackers to execute arbitrary code via long values for certain Proxy configuration parameters.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0444">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:citrix:metaframe:1.0::xp"/>
        <cpe-lang:fact-ref name="cpe:/a:citrix:metaframe_presentation_server:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:citrix:metaframe_presentation_server:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:citrix:metaframe:1.0::xp</vuln:product>
      <vuln:product>cpe:/a:citrix:metaframe_presentation_server:3.0</vuln:product>
      <vuln:product>cpe:/a:citrix:metaframe_presentation_server:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0444</vuln:cve-id>
    <vuln:published-datetime>2007-01-24T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:36.747-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017553" xml:lang="en">1017553</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.citrix.com/article/CTX111686" xml:lang="en">http://support.citrix.com/article/CTX111686</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458002/100/0/threaded" xml:lang="en">20070124 ZDI-07-006: Citrix Metaframe Presentation Server Print Provider Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22217" xml:lang="en">22217</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/data/vulnerabilities/exploits/testlpc.c" xml:lang="en">http://www.securityfocus.com/data/vulnerabilities/exploits/testlpc.c</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0328" xml:lang="en">ADV-2007-0328</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-07-006.html" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-07-006.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in the print provider library (cpprov.dll) in Citrix Presentation Server 4.0, MetaFrame Presentation Server 3.0, and MetaFrame XP 1.0 allows local users and remote attackers to execute arbitrary code via long arguments to the (1) EnumPrintersW and (2) OpenPrinter functions.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0445">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:kaspersky_lab:kaspersky_anti-virus:6.0::file_servers"/>
        <cpe-lang:fact-ref name="cpe:/a:kaspersky_lab:kaspersky_anti-virus:6.0::windows_workstation"/>
        <cpe-lang:fact-ref name="cpe:/a:kaspersky_lab:kaspersky_anti-virus:6.0::workstations"/>
        <cpe-lang:fact-ref name="cpe:/a:kaspersky_lab:kaspersky_internet_security:6.0:maintenance_pack_2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kaspersky_lab:kaspersky_anti-virus:6.0::file_servers</vuln:product>
      <vuln:product>cpe:/a:kaspersky_lab:kaspersky_anti-virus:6.0::windows_workstation</vuln:product>
      <vuln:product>cpe:/a:kaspersky_lab:kaspersky_anti-virus:6.0::workstations</vuln:product>
      <vuln:product>cpe:/a:kaspersky_lab:kaspersky_internet_security:6.0:maintenance_pack_2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0445</vuln:cve-id>
    <vuln:published-datetime>2007-04-05T20:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:37.340-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kaspersky.com/technews?id=203038693" xml:lang="en">http://www.kaspersky.com/technews?id=203038693</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kaspersky.com/technews?id=203038694" xml:lang="en">http://www.kaspersky.com/technews?id=203038694</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/464878/100/0/threaded" xml:lang="en">20070405 ZDI-07-013: Kaspersky AntiVirus Engine ARJ Archive Parsing Heap Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23346" xml:lang="en">23346</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017882" xml:lang="en">1017882</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017883" xml:lang="en">1017883</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1268" xml:lang="en">ADV-2007-1268</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-07-013.html" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-07-013.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33489" xml:lang="en">kaspersky-arj-bo(33489)</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in the arj.ppl module in the OnDemand Scanner in Kaspersky Anti-Virus, Anti-Virus for Workstations, and Anti-Virus for File Servers 6.0, and Internet Security 6.0 before Maintenance Pack 2 build 6.0.2.614 allows remote attackers to execute arbitrary code via crafted ARJ archives.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0446">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:hp:mercury_loadrunner_agent:8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:mercury_loadrunner_agent:8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:mercury_monitor_over_firewall:8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:mercury_performance_center_agent:8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:hp:mercury_performance_center_agent:8.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hp:mercury_loadrunner_agent:8.0</vuln:product>
      <vuln:product>cpe:/a:hp:mercury_loadrunner_agent:8.1</vuln:product>
      <vuln:product>cpe:/a:hp:mercury_monitor_over_firewall:8.1</vuln:product>
      <vuln:product>cpe:/a:hp:mercury_performance_center_agent:8.0</vuln:product>
      <vuln:product>cpe:/a:hp:mercury_performance_center_agent:8.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0446</vuln:cve-id>
    <vuln:published-datetime>2007-02-08T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:38.010-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00854250" xml:lang="en">HPSBGN02187</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017611" xml:lang="en">1017611</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017612" xml:lang="en">1017612</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017613" xml:lang="en">1017613</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/r-123.shtml" xml:lang="en">R-123</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/303012" xml:lang="en">VU#303012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459505/100/0/threaded" xml:lang="en">20070208 ZDI-07-007: HP Mercury LoadRunner Agent Stack Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22487" xml:lang="en">22487</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0535" xml:lang="en">ADV-2007-0535</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-07-007.html" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-07-007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32390" xml:lang="en">mercury-multiple-agent-bo(32390)</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in magentproc.exe for Hewlett-Packard Mercury LoadRunner Agent 8.0 and 8.1, Performance Center Agent 8.0 and 8.1, and Monitor over Firewall 8.1 allows remote attackers to execute arbitrary code via a packet with a long server_ip_name field to TCP port 54345, which triggers the overflow in mchan.dll.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0447">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus_scan_engine:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus_scan_engine:4.0::clearswift"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus_scan_engine:4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus_scan_engine:4.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus_scan_engine:4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus_scan_engine:4.3::caching"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus_scan_engine:4.3::clearswift"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus_scan_engine:4.3::microsoft_sharepoint"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus_scan_engine:4.3::network_attached_storage"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus_scan_engine:4.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus_scan_engine:4.3.7.27"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus_scan_engine:4.3.8.29"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus_scan_engine:4.3.12"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus_scan_engine:4.3.12::caching"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus_scan_engine:4.3.12::clearswift"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus_scan_engine:4.3.12::messaging"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus_scan_engine:4.3.12::microsoft_sharepoint"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus_scan_engine:4.3.12::network_attached_storage"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus_scan_engine:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:antivirus_scan_engine:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:brightmail_antispam:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:brightmail_antispam:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:brightmail_antispam:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:brightmail_antispam:6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:brightmail_antispam:6.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:brightmail_antispam:6.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:brightmail_antispam:6.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:2.0::scf_7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:2.0:build_9.0.0.338:stm"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:2.0.1_build_9.0.1.1000:mr1"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:2.0.2_build_9.0.2.1000:mr2"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:2.0.3_build_9.0.3.1000:mr3"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:2.0.4:mr4_build1000"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:2.0.5_build_1100_mp1:mr5"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:2.0.6:mr6"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.0.359"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.1.1000"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.1.1001"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.1.1007"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.1.1008"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.2.2000"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.2.2001"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.2.2002"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.2.2010"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.2.2011"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.2.2020"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.0.2.2021"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.1.394"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.1.396"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.1.400"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:client_security:3.1.401"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:mail_security:4.0::domino"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:mail_security:4.0::microsoft_exchange"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:mail_security:4.0:build456:microsoft_exchange"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:mail_security:4.0:build463:microsoft_exchange"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:mail_security:4.0:build465:microsoft_exchange"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:mail_security:4.0:build736:microsoft_exchange"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:mail_security:4.0:build741:microsoft_exchange"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:mail_security:4.0:build743:microsoft_exchange"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:mail_security:4.0.1::domino"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:mail_security:4.1:build458:microsoft_exchange"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:mail_security:4.1:build459:microsoft_exchange"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:mail_security:4.1:build461:microsoft_exchange"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:mail_security:4.5::microsoft_exchange"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:mail_security:4.5.4.743::microsoft_exchange"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:mail_security:4.5_build_719::exchange"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:mail_security:4.5_build_736::exchange"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:mail_security:4.5_build_741::exchange"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:mail_security:4.6.1.107::microsoft_exchange"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:mail_security:4.6.3::microsoft_exchange"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:mail_security:4.6_build_97::exchange"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:mail_security:5.0::microsoft_exchange"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:mail_security:5.0::smtp"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:mail_security:5.0.0.204::microsoft_exchange"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:mail_security:5.0.1::smtp"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:mail_security:5.1.0::domino"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:mail_security:6.0.0::microsoft_exchange"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:::corporate_edition_for_linux"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:9.0::corporate_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:9.0::macintosh"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:9.0.0::macintosh"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:9.0.0.338::corporate_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:9.0.1::macintosh"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:9.0.1.1.1000::corporate_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:9.0.2::macintosh"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:9.0.2.1000::corporate_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:9.0.3::macintosh"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:9.0.3.1000::corporate_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:9.0.4::corporate_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:9.0.4:mr4_build_1000:corporate_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:9.0.5::corporate_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:9.0.5.1100::corporate_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:9.0.6.1000::corporate_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:10.0::corporate_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:10.0::macintosh"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:10.0.0::macintosh"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:10.0.0.359::corporate_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:10.0.1::macintosh"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:10.0.1.1000::corporate_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:10.0.1.1007::corporate_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:10.0.1.1008::corporate_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:10.0.2.2000::corporate_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:10.0.2.2001::corporate_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:10.0.2.2002::corporate_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:10.0.2.2010::corporate_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:10.0.2.2011::corporate_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:10.0.2.2020::corporate_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:10.0.2.2021::corporate_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:10.1::corporate_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:10.1.4::corporate_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:10.1.4:mr4_mp1_build4010:corporate_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:10.1.4.4010::corporate_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:10.1.394::corporate_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:10.1.396::corporate_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:10.1.400::corporate_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:10.1.401::corporate_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:10.9.1::macintosh"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:2004"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:2004::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:2005"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:2005::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:2005:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:2005:11.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_antivirus:2006"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_internet_security:3.0::macintosh"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_internet_security:2004"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_internet_security:2004::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_internet_security:2005"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_internet_security:2005::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_internet_security:2005:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_internet_security:2005:11.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_internet_security:2005:11.5.6.14"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_internet_security:2006"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_internet_security:2006::professional"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_personal_firewall:2006"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_personal_firewall:2006_9.1.0.33"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_personal_firewall:2006_9.1.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_system_works:3.0::macintosh"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_system_works:2004"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_system_works:2005"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_system_works:2005::premier"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_system_works:2005:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_system_works:2005:11.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:norton_system_works:2006"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:symantec_antivirus_filtering_%2bfor_domino:3.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:web_security:2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:web_security:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:web_security:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:web_security:3.0.1.70"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:web_security:3.0.1.76"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:web_security:3.0.1_build_3.01.70"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:web_security:3.0.1_build_3.01.72"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:web_security:3.0.1_build_3.01.74"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:web_security:3.01.59"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:web_security:3.01.60"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:web_security:3.01.61"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:web_security:3.01.62"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:web_security:3.01.63"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:web_security:3.01.67"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:web_security:3.01.68"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:web_security:5.0::microsoft_isa_2004"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:symantec:gateway_security_5000_series:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/h:symantec:gateway_security_5400:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/h:symantec:mail_security_8820_appliance"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:symantec:antivirus_scan_engine:4.0</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus_scan_engine:4.0::clearswift</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus_scan_engine:4.1</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus_scan_engine:4.1.8</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus_scan_engine:4.3</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus_scan_engine:4.3::caching</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus_scan_engine:4.3::clearswift</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus_scan_engine:4.3::microsoft_sharepoint</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus_scan_engine:4.3::network_attached_storage</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus_scan_engine:4.3.3</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus_scan_engine:4.3.7.27</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus_scan_engine:4.3.8.29</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus_scan_engine:4.3.12</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus_scan_engine:4.3.12::caching</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus_scan_engine:4.3.12::clearswift</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus_scan_engine:4.3.12::messaging</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus_scan_engine:4.3.12::microsoft_sharepoint</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus_scan_engine:4.3.12::network_attached_storage</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus_scan_engine:5.0</vuln:product>
      <vuln:product>cpe:/a:symantec:antivirus_scan_engine:5.0.1</vuln:product>
      <vuln:product>cpe:/a:symantec:brightmail_antispam:4.0</vuln:product>
      <vuln:product>cpe:/a:symantec:brightmail_antispam:5.5</vuln:product>
      <vuln:product>cpe:/a:symantec:brightmail_antispam:6.0</vuln:product>
      <vuln:product>cpe:/a:symantec:brightmail_antispam:6.0.1</vuln:product>
      <vuln:product>cpe:/a:symantec:brightmail_antispam:6.0.2</vuln:product>
      <vuln:product>cpe:/a:symantec:brightmail_antispam:6.0.3</vuln:product>
      <vuln:product>cpe:/a:symantec:brightmail_antispam:6.0.4</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:2.0</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:2.0::scf_7.1</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:2.0:build_9.0.0.338:stm</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:2.0.1_build_9.0.1.1000:mr1</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:2.0.2_build_9.0.2.1000:mr2</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:2.0.3_build_9.0.3.1000:mr3</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:2.0.4</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:2.0.4:mr4_build1000</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:2.0.5_build_1100_mp1:mr5</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:2.0.6:mr6</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.0.359</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.1.1000</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.1.1001</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.1.1007</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.1.1008</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.2.2000</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.2.2001</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.2.2002</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.2.2010</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.2.2011</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.2.2020</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.0.2.2021</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.1</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.1.394</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.1.396</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.1.400</vuln:product>
      <vuln:product>cpe:/a:symantec:client_security:3.1.401</vuln:product>
      <vuln:product>cpe:/a:symantec:mail_security:4.0::domino</vuln:product>
      <vuln:product>cpe:/a:symantec:mail_security:4.0::microsoft_exchange</vuln:product>
      <vuln:product>cpe:/a:symantec:mail_security:4.0:build456:microsoft_exchange</vuln:product>
      <vuln:product>cpe:/a:symantec:mail_security:4.0:build463:microsoft_exchange</vuln:product>
      <vuln:product>cpe:/a:symantec:mail_security:4.0:build465:microsoft_exchange</vuln:product>
      <vuln:product>cpe:/a:symantec:mail_security:4.0:build736:microsoft_exchange</vuln:product>
      <vuln:product>cpe:/a:symantec:mail_security:4.0:build741:microsoft_exchange</vuln:product>
      <vuln:product>cpe:/a:symantec:mail_security:4.0:build743:microsoft_exchange</vuln:product>
      <vuln:product>cpe:/a:symantec:mail_security:4.0.1::domino</vuln:product>
      <vuln:product>cpe:/a:symantec:mail_security:4.1:build458:microsoft_exchange</vuln:product>
      <vuln:product>cpe:/a:symantec:mail_security:4.1:build459:microsoft_exchange</vuln:product>
      <vuln:product>cpe:/a:symantec:mail_security:4.1:build461:microsoft_exchange</vuln:product>
      <vuln:product>cpe:/a:symantec:mail_security:4.5::microsoft_exchange</vuln:product>
      <vuln:product>cpe:/a:symantec:mail_security:4.5.4.743::microsoft_exchange</vuln:product>
      <vuln:product>cpe:/a:symantec:mail_security:4.5_build_719::exchange</vuln:product>
      <vuln:product>cpe:/a:symantec:mail_security:4.5_build_736::exchange</vuln:product>
      <vuln:product>cpe:/a:symantec:mail_security:4.5_build_741::exchange</vuln:product>
      <vuln:product>cpe:/a:symantec:mail_security:4.6.1.107::microsoft_exchange</vuln:product>
      <vuln:product>cpe:/a:symantec:mail_security:4.6.3::microsoft_exchange</vuln:product>
      <vuln:product>cpe:/a:symantec:mail_security:4.6_build_97::exchange</vuln:product>
      <vuln:product>cpe:/a:symantec:mail_security:5.0::microsoft_exchange</vuln:product>
      <vuln:product>cpe:/a:symantec:mail_security:5.0::smtp</vuln:product>
      <vuln:product>cpe:/a:symantec:mail_security:5.0.0.204::microsoft_exchange</vuln:product>
      <vuln:product>cpe:/a:symantec:mail_security:5.0.1::smtp</vuln:product>
      <vuln:product>cpe:/a:symantec:mail_security:5.1.0::domino</vuln:product>
      <vuln:product>cpe:/a:symantec:mail_security:6.0.0::microsoft_exchange</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:::corporate_edition_for_linux</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:9.0::corporate_edition</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:9.0::macintosh</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:9.0.0::macintosh</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:9.0.0.338::corporate_edition</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:9.0.1::macintosh</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:9.0.1.1.1000::corporate_edition</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:9.0.2::macintosh</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:9.0.2.1000::corporate_edition</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:9.0.3::macintosh</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:9.0.3.1000::corporate_edition</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:9.0.4::corporate_edition</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:9.0.4:mr4_build_1000:corporate_edition</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:9.0.5::corporate_edition</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:9.0.5.1100::corporate_edition</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:9.0.6.1000::corporate_edition</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:10.0::corporate_edition</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:10.0::macintosh</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:10.0.0::macintosh</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:10.0.0.359::corporate_edition</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:10.0.1::macintosh</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:10.0.1.1000::corporate_edition</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:10.0.1.1007::corporate_edition</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:10.0.1.1008::corporate_edition</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:10.0.2.2000::corporate_edition</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:10.0.2.2001::corporate_edition</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:10.0.2.2002::corporate_edition</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:10.0.2.2010::corporate_edition</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:10.0.2.2011::corporate_edition</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:10.0.2.2020::corporate_edition</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:10.0.2.2021::corporate_edition</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:10.1::corporate_edition</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:10.1.4::corporate_edition</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:10.1.4:mr4_mp1_build4010:corporate_edition</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:10.1.4.4010::corporate_edition</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:10.1.394::corporate_edition</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:10.1.396::corporate_edition</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:10.1.400::corporate_edition</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:10.1.401::corporate_edition</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:10.9.1::macintosh</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:2004</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:2004::professional</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:2005</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:2005::professional</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:2005:11.0</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:2005:11.0.9</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_antivirus:2006</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_internet_security:3.0::macintosh</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_internet_security:2004</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_internet_security:2004::professional</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_internet_security:2005</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_internet_security:2005::professional</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_internet_security:2005:11.0</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_internet_security:2005:11.0.9</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_internet_security:2005:11.5.6.14</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_internet_security:2006</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_internet_security:2006::professional</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_personal_firewall:2006</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_personal_firewall:2006_9.1.0.33</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_personal_firewall:2006_9.1.1.7</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_system_works:3.0::macintosh</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_system_works:2004</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_system_works:2005</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_system_works:2005::premier</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_system_works:2005:11.0</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_system_works:2005:11.0.9</vuln:product>
      <vuln:product>cpe:/a:symantec:norton_system_works:2006</vuln:product>
      <vuln:product>cpe:/a:symantec:symantec_antivirus_filtering_%2bfor_domino:3.0.12</vuln:product>
      <vuln:product>cpe:/a:symantec:web_security:2.5</vuln:product>
      <vuln:product>cpe:/a:symantec:web_security:3.0</vuln:product>
      <vuln:product>cpe:/a:symantec:web_security:3.0.1</vuln:product>
      <vuln:product>cpe:/a:symantec:web_security:3.0.1.70</vuln:product>
      <vuln:product>cpe:/a:symantec:web_security:3.0.1.76</vuln:product>
      <vuln:product>cpe:/a:symantec:web_security:3.0.1_build_3.01.70</vuln:product>
      <vuln:product>cpe:/a:symantec:web_security:3.0.1_build_3.01.72</vuln:product>
      <vuln:product>cpe:/a:symantec:web_security:3.0.1_build_3.01.74</vuln:product>
      <vuln:product>cpe:/a:symantec:web_security:3.01.59</vuln:product>
      <vuln:product>cpe:/a:symantec:web_security:3.01.60</vuln:product>
      <vuln:product>cpe:/a:symantec:web_security:3.01.61</vuln:product>
      <vuln:product>cpe:/a:symantec:web_security:3.01.62</vuln:product>
      <vuln:product>cpe:/a:symantec:web_security:3.01.63</vuln:product>
      <vuln:product>cpe:/a:symantec:web_security:3.01.67</vuln:product>
      <vuln:product>cpe:/a:symantec:web_security:3.01.68</vuln:product>
      <vuln:product>cpe:/a:symantec:web_security:5.0::microsoft_isa_2004</vuln:product>
      <vuln:product>cpe:/h:symantec:gateway_security_5000_series:3.0.1</vuln:product>
      <vuln:product>cpe:/h:symantec:gateway_security_5400:2.0.1</vuln:product>
      <vuln:product>cpe:/h:symantec:mail_security_8820_appliance</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0447</vuln:cve-id>
    <vuln:published-datetime>2007-10-05T17:17:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2012-10-30T22:28:08.450-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://securityresponse.symantec.com/avcenter/security/Content/2007.07.11f.html" xml:lang="en">http://securityresponse.symantec.com/avcenter/security/Content/2007.07.11f.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/24282" xml:lang="en">24282</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2508" xml:lang="en">ADV-2007-2508</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-07-040.html" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-07-040.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in the Decomposer component in multiple Symantec products allows remote attackers to execute arbitrary code via multiple crafted CAB archives.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0448">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:php:5.2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0448</vuln:cve-id>
    <vuln:published-datetime>2007-05-24T14:30:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:49:19.397-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-05-29T10:25:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASONRES</vuln:source>
      <vuln:reference href="http://securityreason.com/achievement_securityalert/44" xml:lang="en">20070125 PHP 5.2.0 safe_mode bypass (by Writing Mode)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2175" xml:lang="en">2175</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22261" xml:lang="en">22261</vuln:reference>
    </vuln:references>
    <vuln:summary>The fopen function in PHP 5.2.0 does not properly handle invalid URI handlers, which allows context-dependent attackers to bypass safe_mode restrictions and read arbitrary files via a file path specified with an invalid URI, as demonstrated via the srpath URI.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0449">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ca:brightstor_arcserve_backup_laptops_desktops:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:brightstor_arcserve_backup_laptops_desktops:11.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:brightstor_arcserve_backup_laptops_desktops:11.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:brightstor_mobile_backup:r4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:business_protection_suite:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:desktop_management_suite:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:desktop_management_suite:11.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:desktop_protection_suite:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ca:brightstor_arcserve_backup_laptops_desktops:11.0</vuln:product>
      <vuln:product>cpe:/a:ca:brightstor_arcserve_backup_laptops_desktops:11.1</vuln:product>
      <vuln:product>cpe:/a:ca:brightstor_arcserve_backup_laptops_desktops:11.1:sp1</vuln:product>
      <vuln:product>cpe:/a:ca:brightstor_mobile_backup:r4.0</vuln:product>
      <vuln:product>cpe:/a:ca:business_protection_suite:2.0</vuln:product>
      <vuln:product>cpe:/a:ca:desktop_management_suite:11.0</vuln:product>
      <vuln:product>cpe:/a:ca:desktop_management_suite:11.1</vuln:product>
      <vuln:product>cpe:/a:ca:desktop_protection_suite:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0449</vuln:cve-id>
    <vuln:published-datetime>2007-01-23T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:38.857-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017548" xml:lang="en">1017548</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://supportconnectw.ca.com/public/sams/lifeguard/infodocs/babldimpsec-notice.asp" xml:lang="en">http://supportconnectw.ca.com/public/sams/lifeguard/infodocs/babldimpsec-notice.asp</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/357308" xml:lang="en">VU#357308</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/611276" xml:lang="en">VU#611276</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457945/30/8460/threaded" xml:lang="en">20070124 [CAID 34993]: CA BrightStor ARCserve Backup for Laptops and Desktops Multiple Overflow Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458644/100/0/threaded" xml:lang="en">20070131 Remote Unauthenticated Code Execution CA BrightStor ARCserve Backup</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458648/100/0/threaded" xml:lang="en">20070131 Remote Unauthenticated Code Execution II CA BrightStor ARCserve Backup for Laptops &amp; Desktops</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22199" xml:lang="en">22199</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22340" xml:lang="en">22340</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22342" xml:lang="en">22342</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0314" xml:lang="en">ADV-2007-0314</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www3.ca.com/securityadvisor/newsinfo/collateral.aspx?cid=97696" xml:lang="en">http://www3.ca.com/securityadvisor/newsinfo/collateral.aspx?cid=97696</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www3.ca.com/securityadvisor/vulninfo/Vuln.aspx?ID=34993" xml:lang="en">http://www3.ca.com/securityadvisor/vulninfo/Vuln.aspx?ID=34993</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31704" xml:lang="en">ca-multiple-unspecified-bo(31704)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in LGSERVER.EXE in CA BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.1 SP1, Mobile Backup r4.0, Desktop and Business Protection Suite r2, and Desktop Management Suite (DMS) r11.0 and r11.1 allow remote attackers to execute arbitrary code via crafted packets to TCP port (1) 1900 or (2) 2200.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0450">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:-"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.19"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.21"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.22"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.23"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.24"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.25"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.26"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.27"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.28"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.29"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.30"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.9"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.10"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.11"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.12"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.13"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.14"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.15"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.16"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.17"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.18"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.19"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.20"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.5.21"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.0:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.1:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.2:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.2:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.4:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.6:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.7:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.7:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.8:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.9:beta"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:http_server:-</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.0.0</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.0.1</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.0.2</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.0.3</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.0.4</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.0.5</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.0.6</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.0.7</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.0.8</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.0.9</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.0.10</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.0.11</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.0.12</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.0.13</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.0.14</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.0.15</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.0.16</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.0.17</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.0.18</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.0.19</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.0.21</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.0.22</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.0.23</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.0.24</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.0.25</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.0.26</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.0.27</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.0.28</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.0.29</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.0.30</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.0</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.1</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.2</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.3</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.4</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.5</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.6</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.7</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.8</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.9</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.10</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.11</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.12</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.13</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.14</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.15</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.16</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.17</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.18</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.19</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.20</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:5.5.21</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.0</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.0:alpha</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.1</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.1:alpha</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.2</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.2:alpha</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.2:beta</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.3</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.4</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.4:alpha</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.5</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.6</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.6:alpha</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.7</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.7:alpha</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.7:beta</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.8</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.8:alpha</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.9</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:6.0.9:beta</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0450</vuln:cve-id>
    <vuln:published-datetime>2007-03-16T18:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-04-15T12:29:03.990-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10643" name="oval:org.mitre.oval:def:10643"/>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspx" xml:lang="en">http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspx</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=306172" xml:lang="en">http://docs.info.apple.com/article.html?artnum=306172</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795" xml:lang="en">SSRT071447</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html" xml:lang="en">APPLE-SA-2007-07-31</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.vmware.com/pipermail/security-announce/2008/000003.html" xml:lang="en">[Security-announce] 20080107 VMSA-2008-0002 Low severity security update for VirtualCenter and ESX Server 3.0.2, and ESX 3.0.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200705-03.xml" xml:lang="en">GLSA-200705-03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2446" xml:lang="en">2446</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-239312-1" xml:lang="en">239312</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2007-206.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2007-206.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=197540" xml:lang="en">http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=197540</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://tomcat.apache.org/security-4.html" xml:lang="en">http://tomcat.apache.org/security-4.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://tomcat.apache.org/security-5.html" xml:lang="en">http://tomcat.apache.org/security-5.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://tomcat.apache.org/security-6.html" xml:lang="en">http://tomcat.apache.org/security-6.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.fujitsu.com/global/support/software/security/products-f/interstage-200702e.html" xml:lang="en">http://www.fujitsu.com/global/support/software/security/products-f/interstage-200702e.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:241" xml:lang="en">MDKSA-2007:241</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_15_sr.html" xml:lang="en">SUSE-SR:2007:015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_5_sr.html" xml:lang="en">SUSE-SR:2007:005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0327.html" xml:lang="en">RHSA-2007:0327</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0360.html" xml:lang="en">RHSA-2007:0360</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0261.html" xml:lang="en">RHSA-2008:0261</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.sec-consult.com/287.html" xml:lang="en">http://www.sec-consult.com/287.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.sec-consult.com/fileadmin/Advisories/20070314-0-apache_tomcat_directory_traversal.txt" xml:lang="en">http://www.sec-consult.com/fileadmin/Advisories/20070314-0-apache_tomcat_directory_traversal.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/462791/100/0/threaded" xml:lang="en">20070314 SEC Consult SA-20070314-0 :: Apache HTTP Server / Tomcat directory traversal</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/485938/100/0/threaded" xml:lang="en">20080108 VMSA-2008-0002 Low severity security update for VirtualCenter and ESX Server 3.0.2, and ESX 3.0.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/500396/100/0/threaded" xml:lang="en">20090124 CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/500412/100/0/threaded" xml:lang="en">20090127 CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities (Updated - v1.1)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22960" xml:lang="en">22960</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/25159" xml:lang="en">25159</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0975" xml:lang="en">ADV-2007-0975</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2732" xml:lang="en">ADV-2007-2732</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/3087" xml:lang="en">ADV-2007-3087</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/3386" xml:lang="en">ADV-2007-3386</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0065" xml:lang="en">ADV-2008-0065</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/1979/references" xml:lang="en">ADV-2008-1979</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2009/0233" xml:lang="en">ADV-2009-0233</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32988" xml:lang="en">tomcat-proxy-directory-traversal(32988)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.apache.org/thread.html/277d42b48b6e9aef50949c0dcc79ce21693091d73da246b3c1981925@%3Cdev.tomcat.apache.org%3E" xml:lang="en">[tomcat-dev] 20190413 svn commit: r1857494 [18/20] - in /tomcat/site/trunk: ./ docs/ xdocs/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5@%3Cdev.tomcat.apache.org%3E" xml:lang="en">[tomcat-dev] 20190319 svn commit: r1855831 [21/30] - in /tomcat/site/trunk: ./ docs/ xdocs/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.apache.org/thread.html/5b7a23e245c93235c503900da854a143596d901bf1a1f67e851a5de4@%3Cdev.tomcat.apache.org%3E" xml:lang="en">[tomcat-dev] 20190415 svn commit: r1857582 [20/22] - in /tomcat/site/trunk: docs/ xdocs/stylesheets/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.apache.org/thread.html/8d2a579bbd977c225c70cb23b0ec54865fb0dab5da3eff1e060c9935@%3Cdev.tomcat.apache.org%3E" xml:lang="en">[tomcat-dev] 20190325 svn commit: r1856174 [25/29] - in /tomcat/site/trunk: docs/ xdocs/ xdocs/stylesheets/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.apache.org/thread.html/ba661b0edd913b39ff129a32d855620dd861883ade05fd88a8ce517d@%3Cdev.tomcat.apache.org%3E" xml:lang="en">[tomcat-dev] 20190319 svn commit: r1855831 [26/30] - in /tomcat/site/trunk: ./ docs/ xdocs/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.apache.org/thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74@%3Cdev.tomcat.apache.org%3E" xml:lang="en">[tomcat-dev] 20190325 svn commit: r1856174 [19/29] - in /tomcat/site/trunk: docs/ xdocs/ xdocs/stylesheets/</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_proxy, mod_rewrite, mod_jk), allows remote attackers to read arbitrary files via a .. (dot dot) sequence with combinations of (1) "/" (slash), (2) "\" (backslash), and (3) URL-encoded backslash (%5C) characters in the URL, which are valid separators in Tomcat but not in Apache.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0451">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apache:spamassassin:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:spamassassin:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:spamassassin:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:spamassassin:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:spamassassin:3.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:spamassassin:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:spamassassin:3.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:spamassassin:3.1.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:spamassassin:3.0.1</vuln:product>
      <vuln:product>cpe:/a:apache:spamassassin:3.0.2</vuln:product>
      <vuln:product>cpe:/a:apache:spamassassin:3.0.3</vuln:product>
      <vuln:product>cpe:/a:apache:spamassassin:3.0.4</vuln:product>
      <vuln:product>cpe:/a:apache:spamassassin:3.1.0</vuln:product>
      <vuln:product>cpe:/a:apache:spamassassin:3.1.1</vuln:product>
      <vuln:product>cpe:/a:apache:spamassassin:3.1.2</vuln:product>
      <vuln:product>cpe:/a:apache:spamassassin:3.1.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0451</vuln:cve-id>
    <vuln:published-datetime>2007-02-16T14:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:36.610-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10018" name="oval:org.mitre.oval:def:10018"/>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2007-0074.html" xml:lang="en">RHSA-2007:0074</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200703-02.xml" xml:lang="en">GLSA-200703-02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://spamassassin.apache.org/advisories/cve-2007-0451.txt" xml:lang="en">http://spamassassin.apache.org/advisories/cve-2007-0451.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://svn.apache.org/repos/asf/spamassassin/branches/3.1/build/announcements/3.1.8.txt" xml:lang="en">http://svn.apache.org/repos/asf/spamassassin/branches/3.1/build/announcements/3.1.8.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:049" xml:lang="en">MDKSA-2007:049</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_6_sr.html" xml:lang="en">SUSE-SR:2007:006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0075.html" xml:lang="en">RHSA-2007:0075</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22584" xml:lang="en">22584</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017666" xml:lang="en">1017666</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0628" xml:lang="en">ADV-2007-0628</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32536" xml:lang="en">spamassassin-url-dos(32536)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1073" xml:lang="en">https://issues.rpath.com/browse/RPL-1073</vuln:reference>
    </vuln:references>
    <vuln:summary>Apache SpamAssassin before 3.1.8 allows remote attackers to cause a denial of service via long URLs in malformed HTML, which triggers "massive memory usage."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0452">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.14a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.20"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.20a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.20b"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.21"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.21a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.21b"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.21c"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.22"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.23"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.23a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.23b"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.23c"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.23d"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:samba:samba:3.0.6</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.7</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.8</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.9</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.10</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.11</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.12</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.13</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.14a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.20</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.20a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.20b</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.21</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.21a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.21b</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.21c</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.22</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.23</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.23a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.23b</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.23c</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.23d</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0452</vuln:cve-id>
    <vuln:published-datetime>2007-02-05T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:45.760-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9758" name="oval:org.mitre.oval:def:9758"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc" xml:lang="en">20070201-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2579" xml:lang="en">FEDORA-2007-219</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2580" xml:lang="en">FEDORA-2007-220</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00943462" xml:lang="en">SSRT071341</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Feb/0002.html" xml:lang="en">SUSE-SA:2007:016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2219" xml:lang="en">2219</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017587" xml:lang="en">1017587</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.476916" xml:lang="en">SSA:2007-038-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200588-1" xml:lang="en">200588</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://us1.samba.org/samba/security/CVE-2007-0452.html" xml:lang="en">http://us1.samba.org/samba/security/CVE-2007-0452.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1257" xml:lang="en">DSA-1257</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200702-01.xml" xml:lang="en">GLSA-200702-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:034" xml:lang="en">MDKSA-2007:034</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0060.html" xml:lang="en">RHSA-2007:0060</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0061.html" xml:lang="en">RHSA-2007:0061</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459167/100/0/threaded" xml:lang="en">20070205 [SAMBA-SECURITY] CVE-2007-0452: Potential DoS against smbd in Samba 3.0.6 - 3.0.23d</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459365/100/0/threaded" xml:lang="en">20070207 rPSA-2007-0026-1 samba samba-swat</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22395" xml:lang="en">22395</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2007/0007" xml:lang="en">2007-0007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-419-1" xml:lang="en">USN-419-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0483" xml:lang="en">ADV-2007-0483</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1278" xml:lang="en">ADV-2007-1278</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32301" xml:lang="en">samba-smbd-filerename-dos(32301)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1005" xml:lang="en">https://issues.rpath.com/browse/RPL-1005</vuln:reference>
    </vuln:references>
    <vuln:summary>smbd in Samba 3.0.6 through 3.0.23d allows remote authenticated users to cause a denial of service (memory and CPU exhaustion) by renaming a file in a way that prevents a request from being removed from the deferred open queue, which triggers an infinite loop.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0453">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.21"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.21a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.21b"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.21c"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.22"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.23"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.23a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.23b"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.23c"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.23d"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:samba:samba:3.0.21</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.21a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.21b</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.21c</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.22</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.23</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.23a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.23b</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.23c</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.23d</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0453</vuln:cve-id>
    <vuln:published-datetime>2007-02-05T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:49.450-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017589" xml:lang="en">1017589</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.476916" xml:lang="en">SSA:2007-038-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://us1.samba.org/samba/security/CVE-2007-0453.html" xml:lang="en">http://us1.samba.org/samba/security/CVE-2007-0453.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OPENPKG</vuln:source>
      <vuln:reference href="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.012.html" xml:lang="en">OpenPKG-SA-2007.012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459168/100/0/threaded" xml:lang="en">20070205 [SAMBA-SECURITY] CVE-2007-0453: Buffer overrun in nss_winbind.so.1 on Solaris</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459365/100/0/threaded" xml:lang="en">20070207 rPSA-2007-0026-1 samba samba-swat</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22410" xml:lang="en">22410</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2007/0007" xml:lang="en">2007-0007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0483" xml:lang="en">ADV-2007-0483</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32231" xml:lang="en">samba-winbind-bo(32231)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1005" xml:lang="en">https://issues.rpath.com/browse/RPL-1005</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the nss_winbind.so.1 library in Samba 3.0.21 through 3.0.23d, as used in the winbindd daemon on Solaris, allows attackers to execute arbitrary code via the (1) gethostbyname and (2) getipnodebyname functions.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0454">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.14a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.20"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.20a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.20b"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.21"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.21a"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.21b"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.21c"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.22"/>
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:3.0.23d"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::alpha"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::arm"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::hppa"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::ia-32"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::ia-64"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::m68k"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::mips"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::mipsel"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::ppc"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::s-390"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.1::alpha"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.1::amd64"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.1::arm"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.1::hppa"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.1::ia-32"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.1::ia-64"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.1::m68k"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.1::mips"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.1::mipsel"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.1::ppc"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.1::s-390"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.1::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:2006"/>
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:2006::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linuxsoft_2007"/>
        <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linuxsoft_2007:::x86_64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:samba:samba:3.0.6</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.7</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.8</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.9</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.10</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.11</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.12</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.13</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.14</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.14a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.20</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.20a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.20b</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.21</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.21a</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.21b</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.21c</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.22</vuln:product>
      <vuln:product>cpe:/a:samba:samba:3.0.23d</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::alpha</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::arm</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::hppa</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::ia-32</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::ia-64</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::m68k</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::mips</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::mipsel</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::ppc</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::s-390</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.0::sparc</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.1</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.1::alpha</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.1::amd64</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.1::arm</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.1::hppa</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.1::ia-32</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.1::ia-64</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.1::m68k</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.1::mips</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.1::mipsel</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.1::ppc</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.1::s-390</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.1::sparc</vuln:product>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux:2006</vuln:product>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux:2006::x86_64</vuln:product>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0</vuln:product>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0::x86_64</vuln:product>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0</vuln:product>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0::x86_64</vuln:product>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linuxsoft_2007</vuln:product>
      <vuln:product>cpe:/o:mandrakesoft:mandrake_linuxsoft_2007:::x86_64</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0454</vuln:cve-id>
    <vuln:published-datetime>2007-02-05T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:50.667-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-134"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017588" xml:lang="en">1017588</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.476916" xml:lang="en">SSA:2007-038-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://us1.samba.org/samba/security/CVE-2007-0454.html" xml:lang="en">http://us1.samba.org/samba/security/CVE-2007-0454.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1257" xml:lang="en">DSA-1257</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200702-01.xml" xml:lang="en">GLSA-200702-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/649732" xml:lang="en">VU#649732</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:034" xml:lang="en">MDKSA-2007:034</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OPENPKG</vuln:source>
      <vuln:reference href="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.012.html" xml:lang="en">OpenPKG-SA-2007.012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459179/100/0/threaded" xml:lang="en">20070205 [SAMBA-SECURITY] CVE-2007-0454: Format string bug in afsacl.so VFS plugin</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459365/100/0/threaded" xml:lang="en">20070207 rPSA-2007-0026-1 samba samba-swat</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22403" xml:lang="en">22403</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2007/0007" xml:lang="en">2007-0007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-419-1" xml:lang="en">USN-419-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0483" xml:lang="en">ADV-2007-0483</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32304" xml:lang="en">samba-afsacl-format-string(32304)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1005" xml:lang="en">https://issues.rpath.com/browse/RPL-1005</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in the afsacl.so VFS module in Samba 3.0.6 through 3.0.23d allows context-dependent attackers to execute arbitrary code via format string specifiers in a filename on an AFS file system, which is not properly handled during Windows ACL mapping.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0455">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gd_graphics_library:gdlib:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:gd_graphics_library:gdlib:2.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:gd_graphics_library:gdlib:2.0.20"/>
        <cpe-lang:fact-ref name="cpe:/a:gd_graphics_library:gdlib:2.0.21"/>
        <cpe-lang:fact-ref name="cpe:/a:gd_graphics_library:gdlib:2.0.22"/>
        <cpe-lang:fact-ref name="cpe:/a:gd_graphics_library:gdlib:2.0.23"/>
        <cpe-lang:fact-ref name="cpe:/a:gd_graphics_library:gdlib:2.0.26"/>
        <cpe-lang:fact-ref name="cpe:/a:gd_graphics_library:gdlib:2.0.27"/>
        <cpe-lang:fact-ref name="cpe:/a:gd_graphics_library:gdlib:2.0.28"/>
        <cpe-lang:fact-ref name="cpe:/a:gd_graphics_library:gdlib:2.0.33"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gd_graphics_library:gdlib:2.0.1</vuln:product>
      <vuln:product>cpe:/a:gd_graphics_library:gdlib:2.0.15</vuln:product>
      <vuln:product>cpe:/a:gd_graphics_library:gdlib:2.0.20</vuln:product>
      <vuln:product>cpe:/a:gd_graphics_library:gdlib:2.0.21</vuln:product>
      <vuln:product>cpe:/a:gd_graphics_library:gdlib:2.0.22</vuln:product>
      <vuln:product>cpe:/a:gd_graphics_library:gdlib:2.0.23</vuln:product>
      <vuln:product>cpe:/a:gd_graphics_library:gdlib:2.0.26</vuln:product>
      <vuln:product>cpe:/a:gd_graphics_library:gdlib:2.0.27</vuln:product>
      <vuln:product>cpe:/a:gd_graphics_library:gdlib:2.0.28</vuln:product>
      <vuln:product>cpe:/a:gd_graphics_library:gdlib:2.0.33</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0455</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:52.870-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11303" name="oval:org.mitre.oval:def:11303"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=224607" xml:lang="en">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=224607</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2631" xml:lang="en">FEDORA-2007-150</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052848.html" xml:lang="en">FEDORA-2010-19033</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052854.html" xml:lang="en">FEDORA-2010-19022</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.rpath.com/pipermail/security-announce/2007-February/000145.html" xml:lang="en">[security-announce] 20070208 rPSA-2007-0028-1 gd</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2007-0155.html" xml:lang="en">RHSA-2007:0155</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:035" xml:lang="en">MDKSA-2007:035</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:036" xml:lang="en">MDKSA-2007:036</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:038" xml:lang="en">MDKSA-2007:038</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:109" xml:lang="en">MDKSA-2007:109</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0153.html" xml:lang="en">RHSA-2007:0153</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0162.html" xml:lang="en">RHSA-2007:0162</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0146.html" xml:lang="en">RHSA-2008:0146</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/466166/100/0/threaded" xml:lang="en">20070418 rPSA-2007-0073-1 php php-mysql php-pgsql</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22289" xml:lang="en">22289</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2007/0007" xml:lang="en">2007-0007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-473-1" xml:lang="en">USN-473-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0400" xml:lang="en">ADV-2007-0400</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2011/0022" xml:lang="en">ADV-2011-0022</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1030" xml:lang="en">https://issues.rpath.com/browse/RPL-1030</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1268" xml:lang="en">https://issues.rpath.com/browse/RPL-1268</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the gdImageStringFTEx function in gdft.c in GD Graphics Library 2.0.33 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted string with a JIS encoded font.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0456">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:0.99.3"/>
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:0.99.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wireshark:wireshark:0.99.3</vuln:product>
      <vuln:product>cpe:/a:wireshark:wireshark:0.99.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0456</vuln:cve-id>
    <vuln:published-datetime>2007-02-02T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:36.860-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11342" name="oval:org.mitre.oval:def:11342"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14867" name="oval:org.mitre.oval:def:14867"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" xml:lang="en">20070301-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2565" xml:lang="en">FEDORA-2007-207</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017581" xml:lang="en">1017581</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2007-166.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2007-166.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:033" xml:lang="en">MDKSA-2007:033</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0066.html" xml:lang="en">RHSA-2007:0066</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22352" xml:lang="en">22352</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0443" xml:lang="en">ADV-2007-0443</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.wireshark.org/security/wnpa-sec-2007-01.html" xml:lang="en">http://www.wireshark.org/security/wnpa-sec-2007-01.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32056" xml:lang="en">wireshark-lltdissector-dos(32056)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-985" xml:lang="en">https://issues.rpath.com/browse/RPL-985</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the LLT dissector in Wireshark (formerly Ethereal) 0.99.3 and 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0457">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:0.10.2"/>
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:0.10.3"/>
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:0.10.4"/>
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:0.10.5"/>
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:0.10.6"/>
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:0.10.7"/>
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:0.10.8"/>
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:0.10.9"/>
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:0.10.14"/>
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:0.99.0"/>
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:0.99.2"/>
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:0.99.3"/>
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:0.99.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wireshark:wireshark:0.10.2</vuln:product>
      <vuln:product>cpe:/a:wireshark:wireshark:0.10.3</vuln:product>
      <vuln:product>cpe:/a:wireshark:wireshark:0.10.4</vuln:product>
      <vuln:product>cpe:/a:wireshark:wireshark:0.10.5</vuln:product>
      <vuln:product>cpe:/a:wireshark:wireshark:0.10.6</vuln:product>
      <vuln:product>cpe:/a:wireshark:wireshark:0.10.7</vuln:product>
      <vuln:product>cpe:/a:wireshark:wireshark:0.10.8</vuln:product>
      <vuln:product>cpe:/a:wireshark:wireshark:0.10.9</vuln:product>
      <vuln:product>cpe:/a:wireshark:wireshark:0.10.14</vuln:product>
      <vuln:product>cpe:/a:wireshark:wireshark:0.99.0</vuln:product>
      <vuln:product>cpe:/a:wireshark:wireshark:0.99.2</vuln:product>
      <vuln:product>cpe:/a:wireshark:wireshark:0.99.3</vuln:product>
      <vuln:product>cpe:/a:wireshark:wireshark:0.99.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0457</vuln:cve-id>
    <vuln:published-datetime>2007-02-02T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:36.940-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11003" name="oval:org.mitre.oval:def:11003"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" xml:lang="en">20070301-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2565" xml:lang="en">FEDORA-2007-207</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017581" xml:lang="en">1017581</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2007-166.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2007-166.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:033" xml:lang="en">MDKSA-2007:033</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0066.html" xml:lang="en">RHSA-2007:0066</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22352" xml:lang="en">22352</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0443" xml:lang="en">ADV-2007-0443</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.wireshark.org/security/wnpa-sec-2007-01.html" xml:lang="en">http://www.wireshark.org/security/wnpa-sec-2007-01.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32055" xml:lang="en">wireshark-ieeedissector-dos(32055)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-985" xml:lang="en">https://issues.rpath.com/browse/RPL-985</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the IEEE 802.11 dissector in Wireshark (formerly Ethereal) 0.10.14 through 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0458">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:0.99.3"/>
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:0.99.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wireshark:wireshark:0.99.3</vuln:product>
      <vuln:product>cpe:/a:wireshark:wireshark:0.99.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0458</vuln:cve-id>
    <vuln:published-datetime>2007-02-02T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:37.017-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10966" name="oval:org.mitre.oval:def:10966"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14836" name="oval:org.mitre.oval:def:14836"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" xml:lang="en">20070301-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2565" xml:lang="en">FEDORA-2007-207</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017581" xml:lang="en">1017581</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2007-166.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2007-166.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:033" xml:lang="en">MDKSA-2007:033</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0066.html" xml:lang="en">RHSA-2007:0066</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22352" xml:lang="en">22352</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0443" xml:lang="en">ADV-2007-0443</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.wireshark.org/security/wnpa-sec-2007-01.html" xml:lang="en">http://www.wireshark.org/security/wnpa-sec-2007-01.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32054" xml:lang="en">wireshark-httpdissector-dos(32054)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-985" xml:lang="en">https://issues.rpath.com/browse/RPL-985</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the HTTP dissector in Wireshark (formerly Ethereal) 0.99.3 and 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors, a different issue than CVE-2006-5468.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0459">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:0.99.2"/>
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:0.99.3"/>
        <cpe-lang:fact-ref name="cpe:/a:wireshark:wireshark:0.99.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wireshark:wireshark:0.99.2</vuln:product>
      <vuln:product>cpe:/a:wireshark:wireshark:0.99.3</vuln:product>
      <vuln:product>cpe:/a:wireshark:wireshark:0.99.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0459</vuln:cve-id>
    <vuln:published-datetime>2007-02-02T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:37.097-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10465" name="oval:org.mitre.oval:def:10465"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14875" name="oval:org.mitre.oval:def:14875"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" xml:lang="en">20070301-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://bugs.wireshark.org/bugzilla/show_bug.cgi?id=1200" xml:lang="en">http://bugs.wireshark.org/bugzilla/show_bug.cgi?id=1200</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2565" xml:lang="en">FEDORA-2007-207</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017581" xml:lang="en">1017581</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2007-166.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2007-166.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:033" xml:lang="en">MDKSA-2007:033</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0066.html" xml:lang="en">RHSA-2007:0066</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22352" xml:lang="en">22352</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0443" xml:lang="en">ADV-2007-0443</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.wireshark.org/security/wnpa-sec-2007-01.html" xml:lang="en">http://www.wireshark.org/security/wnpa-sec-2007-01.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32053" xml:lang="en">wireshark-tcpdissector-dos(32053)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-985" xml:lang="en">https://issues.rpath.com/browse/RPL-985</vuln:reference>
    </vuln:references>
    <vuln:summary>packet-tcp.c in the TCP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.4 allows remote attackers to cause a denial of service (application crash or hang) via fragmented HTTP packets.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0460">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9.3"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:10.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:suse:suse_linux:9.3</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:10.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0460</vuln:cve-id>
    <vuln:published-datetime>2007-01-23T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-09-15T01:41:23.013-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200703-17.xml" xml:lang="en">GLSA-200703-17</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:028" xml:lang="en">MDKSA-2007:028</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_01_sr.html" xml:lang="en">SUSE-SR:2007:001</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22139" xml:lang="en">22139</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in ulogd for SUSE Linux 9.3 up to 10.1, and possibly other distributions, have unknown impact and attack vectors related to "improper string length calculations."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0461">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:dazuko:dazuko:2.3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:dazuko:dazuko:2.3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0461</vuln:cve-id>
    <vuln:published-datetime>2007-01-23T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-13T01:32:00.143-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_01_sr.html" xml:lang="en">SUSE-SR:2007:001</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple memory leaks in the Dazuko anti-virus helper module before 2.3.2 allow attackers to cause a denial of service (memory consumption) via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0462">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:quicktime:7.1.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0462</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:12.437-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-23-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-23-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22207" xml:lang="en">22207</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0337" xml:lang="en">ADV-2007-0337</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31698" xml:lang="en">macos-argb-dos(31698)</vuln:reference>
    </vuln:references>
    <vuln:summary>The _GetSrcBits32ARGB function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PICT image with a malformed Alpha RGB (ARGB) record, which triggers memory corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0463">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:software_update:2.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:software_update:2.0.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0463</vuln:cve-id>
    <vuln:published-datetime>2007-01-29T11:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:51.923-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305214" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" xml:lang="en">APPLE-SA-2007-03-13</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-24-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-24-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22222" xml:lang="en">22222</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017755" xml:lang="en">1017755</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" xml:lang="en">TA07-072A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0337" xml:lang="en">ADV-2007-0337</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0930" xml:lang="en">ADV-2007-0930</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in Apple Software Update 2.0.5 on Mac OS X 10.4.8 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via format string specifiers in (1) SWUTMP or (2) SUCATALOG filenames, or using the (3) application/x-apple.sucatalog+xml MIME type.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0464">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.1"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.2"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.3"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.4"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.5"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.7"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.9"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.10"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:cfnetwork:cfnetwork:129.19"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cfnetwork:cfnetwork:129.19</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0464</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:37.173-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307041" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307041</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2007/Nov/msg00002.html" xml:lang="en">APPLE-SA-2007-11-14</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-25-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-25-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22249" xml:lang="en">22249</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/26444" xml:lang="en">26444</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-319A.html" xml:lang="en">TA07-319A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/3868" xml:lang="en">ADV-2007-3868</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31837" xml:lang="en">macos-cfnetwork-dos(31837)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3200" xml:lang="en">3200</vuln:reference>
    </vuln:references>
    <vuln:summary>The _CFNetConnectionWillEnqueueRequests function in CFNetwork 129.19 on Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to cause a denial of service (application crash) via a crafted HTTP 301 response, which results in a NULL pointer dereference.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0465">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:installer:2.1.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:installer:2.1.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0465</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:12.547-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305391" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305391</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" xml:lang="en">APPLE-SA-2007-04-19</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-26-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-26-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22272" xml:lang="en">22272</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017940" xml:lang="en">1017940</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" xml:lang="en">TA07-109A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1470" xml:lang="en">ADV-2007-1470</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31883" xml:lang="en">macos-installer-format-string(31883)</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in Apple Installer 2.1.5 on Mac OS X 10.4.8 allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a (1) PKG, (2) DISTZ, or (3) MPKG package filename.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0466">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:telestream:flip4mac_windows_media_components_for_quicktime:2.1.0.33"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:telestream:flip4mac_windows_media_components_for_quicktime:2.1.0.33</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0466</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:52.423-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-27-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-27-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22286" xml:lang="en">22286</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0389" xml:lang="en">ADV-2007-0389</vuln:reference>
    </vuln:references>
    <vuln:summary>Telestream Flip4Mac Windows Media Components for Quicktime 2.1.0.33 allows remote attackers to execute arbitrary code via a crafted ASF_File_Properties_Object size field in a WMV file, which triggers memory corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0467">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0467</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:12.593-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305214" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" xml:lang="en">APPLE-SA-2007-03-13</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-28-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-28-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/363112" xml:lang="en">VU#363112</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017751" xml:lang="en">1017751</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" xml:lang="en">TA07-072A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0930" xml:lang="en">ADV-2007-0930</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31888" xml:lang="en">macos-crashreporterd-privilege-escalation(31888)</vuln:reference>
    </vuln:references>
    <vuln:summary>crashdump in Apple Mac OS X 10.4.8 allows local users in the admin group to modify arbitrary files or gain privileges via a symlink attack on application logs in /Library/Logs/CrashReporter/.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0468">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visual_studio:6.0:sp6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:visual_studio:6.0:sp6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0468</vuln:cve-id>
    <vuln:published-datetime>2007-01-23T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:55.307-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2172" xml:lang="en">2172</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.anspi.pl/~porkythepig/visualization/rc-kupiekrowe.cpp" xml:lang="en">http://www.anspi.pl/~porkythepig/visualization/rc-kupiekrowe.cpp</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457646/100/0/threaded" xml:lang="en">20070122 Microsoft Visual C++ (.RC) resource files buffer overflow vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0296" xml:lang="en">ADV-2007-0296</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31665" xml:lang="en">visualstudio-rc-bo(31665)</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in rcdll.dll in msdev.exe in Visual C++ (MSVC) in Microsoft Visual Studio 6.0 SP6 allows user-assisted remote attackers to execute arbitrary code via a long file path in the "1 TYPELIB MOVEABLE PURE" option in an RC file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0469">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:rubyforge:rubygems:0.8.11"/>
        <cpe-lang:fact-ref name="cpe:/a:rubyforge:rubygems:0.9.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rubyforge:rubygems:0.8.11</vuln:product>
      <vuln:product>cpe:/a:rubyforge:rubygems:0.9.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0469</vuln:cve-id>
    <vuln:published-datetime>2007-01-23T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:55.777-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://marc.info/?l=full-disclosure&amp;m=116939816621060&amp;w=2" xml:lang="en">20070121 RubyGems 0.9.0 and earlier installation exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://rubyforge.org/frs/shownotes.php?release_id=9074" xml:lang="en">http://rubyforge.org/frs/shownotes.php?release_id=9074</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_4_sr.html" xml:lang="en">SUSE-SR:2007:004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458128/100/0/threaded" xml:lang="en">20070121 RubyGems 0.9.0 and earlier installation exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0295" xml:lang="en">ADV-2007-0295</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31688" xml:lang="en">rubygems-extractfiles-file-overwrite(31688)</vuln:reference>
    </vuln:references>
    <vuln:summary>The extract_files function in installer.rb in RubyGems before 0.9.1 does not check whether files exist before overwriting them, which allows user-assisted remote attackers to overwrite arbitrary files, cause a denial of service, or execute arbitrary code via crafted GEM packages.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0470">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:10.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:10.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0470</vuln:cve-id>
    <vuln:published-datetime>2007-01-23T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:37.090-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2038" name="oval:org.mitre.oval:def:2038"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017546" xml:lang="en">1017546</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102773-1" xml:lang="en">102773</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22190" xml:lang="en">22190</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0317" xml:lang="en">ADV-2007-0317</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31669" xml:lang="en">solaris-tip-privilege-escalation(31669)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple unspecified vulnerabilities in tip in Sun Solaris 8, 9, and 10 allow local users to gain uucp account privileges via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0471">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:checkpoint:connectra_ngx:r62"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:checkpoint:connectra_ngx:r62</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0471</vuln:cve-id>
    <vuln:published-datetime>2007-01-23T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:56.277-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051920.html" xml:lang="en">20070122 Check Point Connectra End Point security bypass</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2179" xml:lang="en">2179</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017559" xml:lang="en">1017559</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017560" xml:lang="en">1017560</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://updates.checkpoint.com/fileserver/ID/7126/FILE/VPN-1_Hotfix1.pdf" xml:lang="en">http://updates.checkpoint.com/fileserver/ID/7126/FILE/VPN-1_Hotfix1.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.checkpoint.com/downloads/latest/hfa/connectra/security_r62.html" xml:lang="en">http://www.checkpoint.com/downloads/latest/hfa/connectra/security_r62.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.checkpoint.com/downloads/latest/hfa/vpn1_security/vpn1_R62_Windows.html" xml:lang="en">http://www.checkpoint.com/downloads/latest/hfa/vpn1_security/vpn1_R62_Windows.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457621/100/0/threaded" xml:lang="en">20070122 Re: [Full-disclosure] Check Point Connectra End Point security bypass</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457683/100/0/threaded" xml:lang="en">20070122 Check Point Connectra End Point security bypass</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0276" xml:lang="en">ADV-2007-0276</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31646" xml:lang="en">checkpoint-params-security-bypass(31646)</vuln:reference>
    </vuln:references>
    <vuln:summary>sre/params.php in the Integrity Clientless Security (ICS) component in Check Point Connectra NGX R62 3.x and earlier before Security Hotfix 5, and possibly VPN-1 NGX R62, allows remote attackers to bypass security requirements via a crafted Report parameter, which returns a valid ICSCookie authentication token.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0472">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:smb4k:smb4k:0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:smb4k:smb4k:0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:smb4k:smb4k:0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:smb4k:smb4k:0.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:smb4k:smb4k:0.4</vuln:product>
      <vuln:product>cpe:/a:smb4k:smb4k:0.5</vuln:product>
      <vuln:product>cpe:/a:smb4k:smb4k:0.6</vuln:product>
      <vuln:product>cpe:/a:smb4k:smb4k:0.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0472</vuln:cve-id>
    <vuln:published-datetime>2007-02-03T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:53.187-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.7</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://developer.berlios.de/bugs/?func=detailbug&amp;bug_id=9630&amp;group_id=769" xml:lang="en">http://developer.berlios.de/bugs/?func=detailbug&amp;bug_id=9630&amp;group_id=769</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://developer.berlios.de/project/shownotes.php?release_id=11706" xml:lang="en">http://developer.berlios.de/project/shownotes.php?release_id=11706</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://developer.berlios.de/project/shownotes.php?release_id=11902" xml:lang="en">http://developer.berlios.de/project/shownotes.php?release_id=11902</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://developer.berlios.de/project/shownotes.php?release_id=9777" xml:lang="en">http://developer.berlios.de/project/shownotes.php?release_id=9777</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0015.html" xml:lang="en">SUSE-SR:2007:002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200703-09.xml" xml:lang="en">GLSA-200703-09</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:042" xml:lang="en">MDKSA-2007:042</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22299" xml:lang="en">22299</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0393" xml:lang="en">ADV-2007-0393</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.berlios.de/pipermail/smb4k-announce/2006-December/000037.html" xml:lang="en">[smb4k-announce] 20061221 Smb4K 0.8.0 and security fixes released</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple race conditions in Smb4K before 0.8.0 allow local users to (1) modify arbitrary files via unspecified manipulations of Smb4K's lock file, which is not properly handled by the remove_lock_file function in core/smb4kfileio.cpp, and (2) add lines to the sudoers file via a symlink attack on temporary files, which isn't properly handled by the writeFile function in core/smb4kfileio.cpp.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0473">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:smb4k:smb4k:0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:smb4k:smb4k:0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:smb4k:smb4k:0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:smb4k:smb4k:0.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:smb4k:smb4k:0.4</vuln:product>
      <vuln:product>cpe:/a:smb4k:smb4k:0.5</vuln:product>
      <vuln:product>cpe:/a:smb4k:smb4k:0.6</vuln:product>
      <vuln:product>cpe:/a:smb4k:smb4k:0.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0473</vuln:cve-id>
    <vuln:published-datetime>2007-02-03T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:53.313-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>1.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://developer.berlios.de/bugs/?func=detailbug&amp;bug_id=9630&amp;group_id=769" xml:lang="en">http://developer.berlios.de/bugs/?func=detailbug&amp;bug_id=9630&amp;group_id=769</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://developer.berlios.de/project/shownotes.php?release_id=11706" xml:lang="en">http://developer.berlios.de/project/shownotes.php?release_id=11706</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://developer.berlios.de/project/shownotes.php?release_id=11902" xml:lang="en">http://developer.berlios.de/project/shownotes.php?release_id=11902</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://developer.berlios.de/project/shownotes.php?release_id=9777" xml:lang="en">http://developer.berlios.de/project/shownotes.php?release_id=9777</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0015.html" xml:lang="en">SUSE-SR:2007:002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200703-09.xml" xml:lang="en">GLSA-200703-09</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:042" xml:lang="en">MDKSA-2007:042</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22299" xml:lang="en">22299</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0393" xml:lang="en">ADV-2007-0393</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.berlios.de/pipermail/smb4k-announce/2006-December/000037.html" xml:lang="en">[smb4k-announce] 20061221 Smb4K 0.8.0 and security fixes released</vuln:reference>
    </vuln:references>
    <vuln:summary>The writeFile function in core/smb4kfileio.cpp in Smb4K before 0.8.0 does not preserve /etc/sudoers permissions across modifications, which allows local users to obtain sensitive information (/etc/sudoers contents) by reading this file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0474">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:smb4k:smb4k:0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:smb4k:smb4k:0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:smb4k:smb4k:0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:smb4k:smb4k:0.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:smb4k:smb4k:0.4</vuln:product>
      <vuln:product>cpe:/a:smb4k:smb4k:0.5</vuln:product>
      <vuln:product>cpe:/a:smb4k:smb4k:0.6</vuln:product>
      <vuln:product>cpe:/a:smb4k:smb4k:0.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0474</vuln:cve-id>
    <vuln:published-datetime>2007-02-03T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:53.627-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.3</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://developer.berlios.de/bugs/?func=detailbug&amp;bug_id=9631&amp;group_id=769" xml:lang="en">http://developer.berlios.de/bugs/?func=detailbug&amp;bug_id=9631&amp;group_id=769</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://developer.berlios.de/project/shownotes.php?release_id=11706" xml:lang="en">http://developer.berlios.de/project/shownotes.php?release_id=11706</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://developer.berlios.de/project/shownotes.php?release_id=11902" xml:lang="en">http://developer.berlios.de/project/shownotes.php?release_id=11902</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://developer.berlios.de/project/shownotes.php?release_id=9777" xml:lang="en">http://developer.berlios.de/project/shownotes.php?release_id=9777</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0015.html" xml:lang="en">SUSE-SR:2007:002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200703-09.xml" xml:lang="en">GLSA-200703-09</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:042" xml:lang="en">MDKSA-2007:042</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22299" xml:lang="en">22299</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0393" xml:lang="en">ADV-2007-0393</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.berlios.de/pipermail/smb4k-announce/2006-December/000037.html" xml:lang="en">[smb4k-announce] 20061221 Smb4K 0.8.0 and security fixes released</vuln:reference>
    </vuln:references>
    <vuln:summary>Smb4K before 0.8.0 allow local users, when present on the Smb4K sudoers list, to kill arbitrary processes, related to a "design issue with smb4k_kill."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0475">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:smb4k:smb4k:0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:smb4k:smb4k:0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:smb4k:smb4k:0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:smb4k:smb4k:0.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:smb4k:smb4k:0.4</vuln:product>
      <vuln:product>cpe:/a:smb4k:smb4k:0.5</vuln:product>
      <vuln:product>cpe:/a:smb4k:smb4k:0.6</vuln:product>
      <vuln:product>cpe:/a:smb4k:smb4k:0.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0475</vuln:cve-id>
    <vuln:published-datetime>2007-02-03T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:53.767-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.4</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://developer.berlios.de/bugs/?func=detailbug&amp;bug_id=9631&amp;group_id=769" xml:lang="en">http://developer.berlios.de/bugs/?func=detailbug&amp;bug_id=9631&amp;group_id=769</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://developer.berlios.de/project/shownotes.php?release_id=11706" xml:lang="en">http://developer.berlios.de/project/shownotes.php?release_id=11706</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://developer.berlios.de/project/shownotes.php?release_id=11902" xml:lang="en">http://developer.berlios.de/project/shownotes.php?release_id=11902</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://developer.berlios.de/project/shownotes.php?release_id=9777" xml:lang="en">http://developer.berlios.de/project/shownotes.php?release_id=9777</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0015.html" xml:lang="en">SUSE-SR:2007:002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200703-09.xml" xml:lang="en">GLSA-200703-09</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:042" xml:lang="en">MDKSA-2007:042</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22299" xml:lang="en">22299</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0393" xml:lang="en">ADV-2007-0393</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.berlios.de/pipermail/smb4k-announce/2006-December/000037.html" xml:lang="en">[smb4k-announce] 20061221 Smb4K 0.8.0 and security fixes released</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple stack-based buffer overflows in utilities/smb4k_*.cpp in Smb4K before 0.8.0 allow local users, when present on the Smb4K sudoers list, to gain privileges via unspecified vectors related to the args variable and unspecified other variables, in conjunction with the sudo configuration.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0476">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:gentoo:linux:2.1.30:r9"/>
        <cpe-lang:fact-ref name="cpe:/o:gentoo:linux:2.2.28:r7"/>
        <cpe-lang:fact-ref name="cpe:/o:gentoo:linux:2.3.30:r2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:gentoo:linux:2.1.30:r9</vuln:product>
      <vuln:product>cpe:/o:gentoo:linux:2.2.28:r7</vuln:product>
      <vuln:product>cpe:/o:gentoo:linux:2.3.30:r2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0476</vuln:cve-id>
    <vuln:published-datetime>2007-01-24T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:53.923-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200701-19.xml" xml:lang="en">GLSA-200701-19</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22195" xml:lang="en">22195</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0305" xml:lang="en">ADV-2007-0305</vuln:reference>
    </vuln:references>
    <vuln:summary>The gencert.sh script, when installing OpenLDAP before 2.1.30-r10, 2.2.x before 2.2.28-r7, and 2.3.x before 2.3.30-r2 as an ebuild in Gentoo Linux, does not create temporary directories in /tmp securely during emerge, which allows local users to overwrite arbitrary files via a symlink attack.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0477">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:openads:openads:2.3.30"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openads:openads:2.3.30</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0477</vuln:cve-id>
    <vuln:published-datetime>2007-01-24T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:57.293-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://forum.openads.org/index.php?showtopic=503412651" xml:lang="en">http://forum.openads.org/index.php?showtopic=503412651</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>JVN</vuln:source>
      <vuln:reference href="http://jvn.jp/jp/JVN%2307274813/index.html" xml:lang="en">JVN#07274813</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457990/100/200/threaded" xml:lang="en">20070124 [OPENADS-SA-2007-001] phpAdsNew and phpPgAds 2.0.9-pr1 vulnerability fixed</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458197/100/100/threaded" xml:lang="en">20070126 [OPENADS-SA-2007-002] Max Media Manager v0.1.29 and v0.3.30 vulnerability fixed</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458296/100/100/threaded" xml:lang="en">20070127 Re: [OPENADS-SA-2007-002] Max Media Manager v0.1.29 and v0.3.30 vulnerability fixed</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0315" xml:lang="en">ADV-2007-0315</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://developer.openads.org/browser/branches/max/trunk/CHANGELOG.txt?format=raw" xml:lang="en">https://developer.openads.org/browser/branches/max/trunk/CHANGELOG.txt?format=raw</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Openads 2.0.x before 2.0.10, 2.3 before 2.3.31 (aka Max Media Manager before 0.3.31-alpha-pr2), and phpAdsNew/phpPgAds before 2.0.9-pr1 allows remote attackers to inject arbitrary web script or HTML via (1) the keyword parameter in admin-search.php and (2) affiliate-search.php. NOTE: this issue may overlap CVE-2007-0363.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0478">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.10"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:apple:safari"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:webcore"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:safari</vuln:product>
      <vuln:product>cpe:/a:apple:webcore</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0478</vuln:cve-id>
    <vuln:published-datetime>2007-01-24T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:57.870-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=306172" xml:lang="en">http://docs.info.apple.com/article.html?artnum=306172</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html" xml:lang="en">APPLE-SA-2007-07-31</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1018494" xml:lang="en">1018494</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.beanfuzz.com/wordpress/?p=99" xml:lang="en">http://www.beanfuzz.com/wordpress/?p=99</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457763/100/0/threaded" xml:lang="en">20070123 Safari Improperly Parses HTML Documents &amp; BlogSpot XSS vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/25159" xml:lang="en">25159</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2732" xml:lang="en">ADV-2007-2732</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31846" xml:lang="en">safari-html-comment-xss(31846)</vuln:reference>
    </vuln:references>
    <vuln:summary>WebCore on Apple Mac OS X 10.3.9 and 10.4.10, as used in Safari, does not properly parse HTML comments in TITLE elements, which allows remote attackers to conduct cross-site scripting (XSS) attacks and bypass some XSS protection schemes by embedding certain HTML tags within an HTML comment.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0479">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0da"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0db"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0dc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0s"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0sc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0sl"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0sp"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0st"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0sx"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0sy"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0sz"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0t"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0w"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0wc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0wt"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xa"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xd"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xe"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xf"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xg"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xh"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xi"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xj"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xk"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xl"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xm"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xq"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xr"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xs"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xv"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xw"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1aa"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1ax"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1ay"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1az"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1cx"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1da"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1db"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1dc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1e"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1ea"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1eb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1ec"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1eo"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1eu"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1ev"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1ew"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1ex"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1ey"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1ez"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1t"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1x"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xa"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xd"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xe"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xf"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xg"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xh"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xi"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xj"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xl"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xp"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xq"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xr"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xs"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xt"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xu"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xv"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xw"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xx"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xy"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xz"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1ya"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1yb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1yc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1yd"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1ye"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1yf"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1yh"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1yi"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1yj"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2b"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2bc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2bw"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2by"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2bz"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2cx"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2cy"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2cz"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2da"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2dd"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2dx"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2eu"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ew"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ewa"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ex"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ey"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ez"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2fx"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2fy"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2fz"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ixa"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ixb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ixc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ja"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2jk"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2mb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2mc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2s"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sbc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2se"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sea"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2seb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sec"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sed"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2see"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sef"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2seg"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sg"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sga"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2so"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sra"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2srb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2su"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sv"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sw"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sx"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sxa"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sxb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sxd"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sxe"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sxf"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sy"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sz"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2t"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2tpc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xa"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xd"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xe"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xf"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xg"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xh"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xi"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xj"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xk"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xl"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xm"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xn"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xq"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xr"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xs"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xt"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xu"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xv"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xw"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ya"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yd"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ye"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yf"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yg"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yh"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yj"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yk"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yl"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ym"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yn"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yo"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yp"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yq"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yr"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ys"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yt"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yu"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yv"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yw"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yx"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yy"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yz"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2za"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2zb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2zc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2zd"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ze"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2zf"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2zg"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2zh"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2zj"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2zl"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2zn"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2zp"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3b"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3bc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3bw"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3ja"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3jea"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3jeb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3jk"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3jx"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3t"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3tpc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xa"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xd"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xe"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xf"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xg"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xh"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xi"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xj"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xk"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xq"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xr"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xs"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xu"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xw"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xx"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xy"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3ya"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3yd"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3yf"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3yg"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3yh"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3yi"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3yj"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3yk"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3ym"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3yq"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3ys"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3yt"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3yu"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3yx"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3yz"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.4"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.4mr"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.4sw"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.4t"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.4xa"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.4xb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.4xc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0da</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0db</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0dc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0s</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0sc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0sl</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0sp</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0st</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0sx</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0sy</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0sz</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0t</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0w</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0wc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0wt</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xa</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xd</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xe</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xf</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xg</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xh</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xi</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xj</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xk</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xl</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xm</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xq</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xr</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xs</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xv</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xw</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1aa</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1ax</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1ay</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1az</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1cx</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1da</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1db</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1dc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1e</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1ea</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1eb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1ec</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1eo</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1eu</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1ev</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1ew</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1ex</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1ey</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1ez</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1t</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1x</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xa</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xd</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xe</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xf</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xg</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xh</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xi</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xj</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xl</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xp</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xq</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xr</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xs</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xt</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xu</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xv</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xw</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xx</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xy</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xz</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1ya</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1yb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1yc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1yd</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1ye</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1yf</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1yh</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1yi</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1yj</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2b</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2bc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2bw</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2by</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2bz</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2cx</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2cy</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2cz</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2da</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2dd</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2dx</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2eu</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ew</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ewa</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ex</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ey</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ez</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2fx</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2fy</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2fz</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ixa</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ixb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ixc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ja</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2jk</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2mb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2mc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2s</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sbc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2se</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sea</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2seb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sec</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sed</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2see</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sef</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2seg</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sg</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sga</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2so</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sra</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2srb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2su</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sv</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sw</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sx</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sxa</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sxb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sxd</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sxe</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sxf</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sy</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sz</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2t</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2tpc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xa</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xd</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xe</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xf</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xg</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xh</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xi</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xj</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xk</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xl</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xm</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xn</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xq</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xr</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xs</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xt</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xu</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xv</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xw</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ya</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yd</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ye</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yf</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yg</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yh</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yj</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yk</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yl</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ym</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yn</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yo</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yp</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yq</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yr</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ys</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yt</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yu</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yv</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yw</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yx</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yy</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yz</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2za</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2zb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2zc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2zd</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ze</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2zf</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2zg</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2zh</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2zj</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2zl</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2zn</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2zp</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3b</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3bc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3bw</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3ja</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3jea</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3jeb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3jk</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3jx</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3t</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3tpc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xa</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xd</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xe</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xf</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xg</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xh</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xi</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xj</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xk</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xq</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xr</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xs</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xu</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xw</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xx</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xy</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3ya</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3yd</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3yf</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3yg</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3yh</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3yi</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3yj</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3yk</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3ym</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3yq</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3ys</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3yt</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3yu</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3yx</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3yz</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.4</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.4mr</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.4sw</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.4t</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.4xa</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.4xb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.4xc</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0479</vuln:cve-id>
    <vuln:published-datetime>2007-01-24T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:37.330-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5080" name="oval:org.mitre.oval:def:5080"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017551" xml:lang="en">1017551</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/en/US/products/products_security_advisory09186a00807cb0e4.shtml" xml:lang="en">20070124 Crafted TCP Packet Can Cause Denial of Service</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/217912" xml:lang="en">VU#217912</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22208" xml:lang="en">22208</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-024A.html" xml:lang="en">TA07-024A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0329" xml:lang="en">ADV-2007-0329</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31716" xml:lang="en">cisco-tcp-ipv4-dos(31716)</vuln:reference>
    </vuln:references>
    <vuln:summary>Memory leak in the TCP listener in Cisco IOS 9.x, 10.x, 11.x, and 12.x allows remote attackers to cause a denial of service by sending crafted TCP traffic to an IPv4 address on the IOS device.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0480">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0da"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0db"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0dc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0s"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0sc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0sl"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0sp"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0st"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0sx"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0sy"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0sz"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0t"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0w"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0wc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0wt"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xa"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xd"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xe"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xf"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xg"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xh"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xi"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xj"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xk"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xl"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xm"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xq"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xr"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xs"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xv"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xw"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1aa"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1ax"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1ay"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1az"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1cx"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1da"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1db"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1dc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1e"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1ea"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1eb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1ec"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1eo"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1eu"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1ev"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1ew"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1ex"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1ey"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1ez"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1t"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1x"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xa"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xd"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xe"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xf"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xg"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xh"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xi"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xj"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xl"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xp"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xq"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xr"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xs"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xt"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xu"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xv"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xw"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xx"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xy"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xz"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1ya"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1yb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1yc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1yd"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1ye"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1yf"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1yh"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1yi"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1yj"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2b"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2bc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2bw"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2by"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2bz"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2cx"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2cy"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2cz"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2da"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2dd"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2dx"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2eu"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ew"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ewa"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ex"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ey"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ez"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2fx"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2fy"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2fz"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ixa"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ixb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ixc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ja"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2jk"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2mb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2mc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2s"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sbc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2se"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sea"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2seb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sec"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sed"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2see"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sef"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2seg"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sg"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sga"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2so"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sra"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2srb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2su"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sv"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sw"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sx"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sxa"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sxb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sxd"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sxe"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sxf"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sy"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sz"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2t"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2tpc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xa"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xd"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xe"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xf"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xg"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xh"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xi"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xj"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xk"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xl"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xm"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xn"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xq"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xr"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xs"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xt"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xu"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xv"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xw"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ya"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yd"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ye"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yf"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yg"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yh"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yj"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yk"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yl"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ym"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yn"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yo"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yp"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yq"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yr"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ys"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yt"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yu"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yv"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yw"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yx"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yy"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yz"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2za"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2zb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2zc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2zd"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ze"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2zf"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2zg"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2zh"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2zj"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2zl"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2zn"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2zp"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3b"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3bc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3bw"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3ja"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3jea"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3jeb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3jk"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3jx"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3t"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3tpc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xa"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xd"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xe"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xf"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xg"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xh"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xi"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xj"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xk"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xq"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xr"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xs"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xu"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xw"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xx"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xy"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3ya"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3yd"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3yf"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3yg"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3yh"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3yi"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3yj"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3yk"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3ym"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3yq"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3ys"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3yt"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3yu"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3yx"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3yz"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.4"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.4mr"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.4sw"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.4t"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.4xa"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.4xb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.4xc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0da</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0db</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0dc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0s</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0sc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0sl</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0sp</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0st</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0sx</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0sy</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0sz</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0t</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0w</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0wc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0wt</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xa</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xd</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xe</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xf</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xg</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xh</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xi</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xj</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xk</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xl</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xm</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xq</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xr</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xs</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xv</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xw</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1aa</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1ax</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1ay</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1az</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1cx</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1da</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1db</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1dc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1e</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1ea</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1eb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1ec</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1eo</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1eu</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1ev</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1ew</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1ex</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1ey</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1ez</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1t</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1x</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xa</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xd</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xe</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xf</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xg</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xh</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xi</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xj</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xl</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xp</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xq</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xr</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xs</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xt</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xu</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xv</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xw</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xx</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xy</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xz</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1ya</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1yb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1yc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1yd</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1ye</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1yf</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1yh</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1yi</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1yj</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2b</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2bc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2bw</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2by</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2bz</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2cx</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2cy</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2cz</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2da</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2dd</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2dx</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2eu</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ew</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ewa</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ex</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ey</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ez</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2fx</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2fy</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2fz</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ixa</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ixb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ixc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ja</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2jk</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2mb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2mc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2s</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sbc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2se</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sea</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2seb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sec</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sed</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2see</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sef</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2seg</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sg</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sga</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2so</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sra</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2srb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2su</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sv</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sw</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sx</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sxa</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sxb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sxd</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sxe</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sxf</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sy</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sz</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2t</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2tpc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xa</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xd</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xe</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xf</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xg</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xh</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xi</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xj</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xk</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xl</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xm</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xn</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xq</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xr</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xs</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xt</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xu</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xv</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xw</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ya</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yd</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ye</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yf</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yg</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yh</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yj</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yk</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yl</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ym</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yn</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yo</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yp</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yq</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yr</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ys</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yt</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yu</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yv</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yw</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yx</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yy</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yz</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2za</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2zb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2zc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2zd</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ze</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2zf</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2zg</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2zh</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2zj</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2zl</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2zn</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2zp</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3b</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3bc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3bw</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3ja</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3jea</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3jeb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3jk</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3jx</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3t</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3tpc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xa</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xd</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xe</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xf</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xg</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xh</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xi</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xj</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xk</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xq</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xr</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xs</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xu</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xw</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xx</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xy</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3ya</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3yd</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3yf</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3yg</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3yh</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3yi</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3yj</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3yk</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3ym</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3yq</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3ys</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3yt</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3yu</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3yx</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3yz</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.4</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.4mr</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.4sw</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.4t</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.4xa</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.4xb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.4xc</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0480</vuln:cve-id>
    <vuln:published-datetime>2007-01-24T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:37.427-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5666" name="oval:org.mitre.oval:def:5666"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017555" xml:lang="en">1017555</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/en/US/products/products_security_advisory09186a00807cb157.shtml" xml:lang="en">20070124 Crafted IP Option Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/341288" xml:lang="en">VU#341288</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22211" xml:lang="en">22211</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-024A.html" xml:lang="en">TA07-024A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0329" xml:lang="en">ADV-2007-0329</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31725" xml:lang="en">cisco-ip-option-code-execution(31725)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cisco IOS 9.x, 10.x, 11.x, and 12.x and IOS XR 2.0.x, 3.0.x, and 3.2.x allows remote attackers to cause a denial of service or execute arbitrary code via a crafted IP option in the IP header in a (1) ICMP, (2) PIMv2, (3) PGM, or (4) URD packet.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0481">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0da"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0db"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0dc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0s"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0sc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0sl"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0sp"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0st"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0sx"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0sy"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0sz"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0t"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0w"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0wc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0wt"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xa"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xd"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xe"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xf"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xg"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xh"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xi"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xj"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xk"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xl"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xm"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xq"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xr"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xs"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xv"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.0xw"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1aa"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1ax"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1ay"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1az"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1cx"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1da"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1db"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1dc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1e"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1ea"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1eb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1ec"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1eo"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1eu"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1ev"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1ew"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1ex"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1ey"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1ez"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1t"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1x"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xa"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xd"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xe"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xf"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xg"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xh"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xi"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xj"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xl"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xp"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xq"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xr"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xs"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xt"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xu"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xv"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xw"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xx"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xy"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1xz"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1ya"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1yb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1yc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1yd"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1ye"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1yf"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1yh"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1yi"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.1yj"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2b"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2bc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2bw"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2by"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2bz"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2cx"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2cy"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2cz"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2da"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2dd"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2dx"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2eu"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ew"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ewa"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ex"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ey"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ez"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2fx"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2fy"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2fz"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ixa"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ixb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ixc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ja"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2jk"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2mb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2mc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2s"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sbc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2se"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sea"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2seb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sec"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sed"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2see"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sef"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2seg"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sg"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sga"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2so"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sra"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2srb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2su"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sv"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sw"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sx"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sxa"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sxb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sxd"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sxe"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sxf"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sy"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2sz"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2t"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2tpc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xa"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xd"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xe"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xf"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xg"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xh"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xi"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xj"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xk"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xl"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xm"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xn"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xq"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xr"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xs"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xt"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xu"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xv"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2xw"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ya"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yd"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ye"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yf"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yg"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yh"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yj"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yk"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yl"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ym"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yn"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yo"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yp"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yq"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yr"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ys"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yt"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yu"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yv"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yw"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yx"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yy"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2yz"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2za"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2zb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2zc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2zd"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2ze"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2zf"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2zg"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2zh"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2zj"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2zl"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2zn"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.2zp"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3b"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3bc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3bw"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3ja"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3jea"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3jeb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3jk"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3jx"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3t"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3tpc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xa"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xc"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xd"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xe"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xf"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xg"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xh"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xi"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xj"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xk"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xq"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xr"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xs"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xu"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xw"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xx"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3xy"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3ya"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3yd"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3yf"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3yg"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3yh"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3yi"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3yj"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3yk"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3ym"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3yq"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3ys"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3yt"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3yu"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3yx"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.3yz"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.4"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.4mr"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.4sw"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.4t"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.4xa"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.4xb"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios_transmission_control_protocol:12.4xc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0da</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0db</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0dc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0s</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0sc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0sl</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0sp</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0st</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0sx</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0sy</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0sz</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0t</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0w</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0wc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0wt</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xa</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xd</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xe</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xf</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xg</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xh</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xi</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xj</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xk</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xl</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xm</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xq</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xr</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xs</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xv</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.0xw</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1aa</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1ax</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1ay</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1az</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1cx</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1da</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1db</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1dc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1e</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1ea</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1eb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1ec</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1eo</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1eu</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1ev</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1ew</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1ex</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1ey</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1ez</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1t</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1x</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xa</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xd</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xe</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xf</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xg</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xh</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xi</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xj</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xl</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xp</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xq</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xr</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xs</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xt</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xu</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xv</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xw</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xx</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xy</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1xz</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1ya</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1yb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1yc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1yd</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1ye</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1yf</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1yh</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1yi</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.1yj</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2b</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2bc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2bw</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2by</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2bz</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2cx</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2cy</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2cz</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2da</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2dd</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2dx</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2eu</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ew</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ewa</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ex</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ey</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ez</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2fx</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2fy</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2fz</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ixa</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ixb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ixc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ja</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2jk</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2mb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2mc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2s</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sbc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2se</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sea</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2seb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sec</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sed</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2see</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sef</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2seg</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sg</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sga</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2so</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sra</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2srb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2su</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sv</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sw</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sx</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sxa</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sxb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sxd</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sxe</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sxf</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sy</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2sz</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2t</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2tpc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xa</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xd</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xe</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xf</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xg</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xh</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xi</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xj</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xk</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xl</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xm</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xn</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xq</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xr</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xs</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xt</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xu</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xv</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2xw</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ya</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yd</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ye</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yf</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yg</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yh</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yj</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yk</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yl</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ym</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yn</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yo</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yp</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yq</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yr</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ys</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yt</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yu</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yv</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yw</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yx</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yy</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2yz</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2za</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2zb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2zc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2zd</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2ze</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2zf</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2zg</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2zh</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2zj</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2zl</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2zn</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.2zp</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3b</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3bc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3bw</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3ja</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3jea</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3jeb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3jk</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3jx</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3t</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3tpc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xa</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xc</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xd</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xe</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xf</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xg</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xh</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xi</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xj</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xk</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xq</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xr</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xs</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xu</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xw</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xx</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3xy</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3ya</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3yd</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3yf</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3yg</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3yh</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3yi</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3yj</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3yk</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3ym</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3yq</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3ys</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3yt</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3yu</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3yx</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.3yz</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.4</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.4mr</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.4sw</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.4t</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.4xa</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.4xb</vuln:product>
      <vuln:product>cpe:/h:cisco:ios_transmission_control_protocol:12.4xc</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0481</vuln:cve-id>
    <vuln:published-datetime>2007-01-24T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:37.517-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5857" name="oval:org.mitre.oval:def:5857"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017550" xml:lang="en">1017550</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/en/US/products/products_security_advisory09186a00807cb0fd.shtml" xml:lang="en">20070124 IPv6 Routing Header Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/274760" xml:lang="en">VU#274760</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22210" xml:lang="en">22210</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-024A.html" xml:lang="en">TA07-024A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0329" xml:lang="en">ADV-2007-0329</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31715" xml:lang="en">cisco-ios-ipv6-type0-dos(31715)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cisco IOS allows remote attackers to cause a denial of service (crash) via a crafted IPv6 Type 0 Routing header.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0482">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sun:ray_server_software:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:ray_server_software:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:ray_server_software:2.0</vuln:product>
      <vuln:product>cpe:/a:sun:ray_server_software:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0482</vuln:cve-id>
    <vuln:published-datetime>2007-01-24T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:13.327-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017547" xml:lang="en">1017547</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102779-1" xml:lang="en">102779</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22192" xml:lang="en">22192</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0316" xml:lang="en">ADV-2007-0316</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31700" xml:lang="en">sunray-utadmin-information-disclosure(31700)</vuln:reference>
    </vuln:references>
    <vuln:summary>cgi-bin/main in Sun Ray Server Software 2.0 and 3.0 before 20070123 allows local users to obtain the utadmin password by reading a web server's log file, or by conducting a different, unspecified local attack.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0483">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:enthusiast:enthusiast:3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:enthusiast:enthusiast:3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0483</vuln:cve-id>
    <vuln:published-datetime>2007-01-24T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:13.377-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22180" xml:lang="en">22180</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31667" xml:lang="en">enthusiast-show-xss(31667)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Enthusiast 3.1 allow remote attackers to inject arbitrary web script or HTML via the URI for (1) show_owned.php or (2) show_joined.php.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0484">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:enthusiast:enthusiast:3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:enthusiast:enthusiast:3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0484</vuln:cve-id>
    <vuln:published-datetime>2007-01-24T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:13.423-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22180" xml:lang="en">22180</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31666" xml:lang="en">enthusiast-show-sql-injection(31666)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in Enthusiast 3.1 allow remote attackers to execute arbitrary SQL commands via the cat parameter to (1) show_owned.php, (2) show_joined.php, and possibly other files. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0485">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:webchat.org:webchat:0.77"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:webchat.org:webchat:0.77</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0485</vuln:cve-id>
    <vuln:published-datetime>2007-01-24T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:58.573-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/313610/30/25700/threaded" xml:lang="en">20030303 WebChat (PHP)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/7000" xml:lang="en">7000</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1006193" xml:lang="en">1006193</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31624" xml:lang="en">webchat-definesphp-file-include(31624)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3169" xml:lang="en">3169</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in defines.php in WebChat 0.77 allows remote attackers to execute arbitrary PHP code via a URL in the WEBCHATPATH parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0486">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpadsnew:phpadsnew:2.0.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpadsnew:phpadsnew:2.0.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0486</vuln:cve-id>
    <vuln:published-datetime>2007-01-24T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:58.997-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2174" xml:lang="en">2174</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457670/100/0/threaded" xml:lang="en">20070120 phpAdsNew 2.0.7 Remote File Include</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457806/100/200/threaded" xml:lang="en">20070122 Re: phpAdsNew 2.0.7 Remote File Include</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457991/100/200/threaded" xml:lang="en">20070124 Re: phpAdsNew 2.0.7 Remote File Include</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22172" xml:lang="en">22172</vuln:reference>
    </vuln:references>
    <vuln:summary>** DISPUTED **  Multiple PHP remote file inclusion vulnerabilities in Openads (aka phpAdsNew) 2.0.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) phpAds_geoPlugin parameter to libraries/lib-remotehost.inc, the (2) filename parameter to admin/report-index, or the (3) phpAds_config[my_footer] parameter to admin/lib-gui.inc.  NOTE: the vendor has disputed this issue, stating that the relevant variables are used within function definitions.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0487">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:zoneo-soft:freeforum:0.9.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:zoneo-soft:freeforum:0.9.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0487</vuln:cve-id>
    <vuln:published-datetime>2007-01-24T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:59.607-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457643/100/0/threaded" xml:lang="en">20070121 FreeForum 0.9.0 &lt;=- (index.php fpath) Remote File Include Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457958/100/0/threaded" xml:lang="en">20070124 Re: FreeForum 0.9.0 &lt;=- (index.php fpath) Remote File Include Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31647" xml:lang="en">freeforum-index-file-include(31647)</vuln:reference>
    </vuln:references>
    <vuln:summary>** DISPUTED **  PHP remote file inclusion vulnerability in index.php in FreeForum 0.9.0 allows remote attackers to execute arbitrary PHP code via a URL in the fpath parameter. NOTE: this issue has been disputed by third party researchers, stating that fpath variable is initialized before being used.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0488">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:huawei:versatile_routing_platform:1.43_2500e-003_firmware"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:huawei:versatile_routing_platform:1.43_2500e-003_firmware</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0488</vuln:cve-id>
    <vuln:published-datetime>2007-01-24T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:13.577-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051856.html" xml:lang="en">20070118 The Quidway Router local DOS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2176" xml:lang="en">2176</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31641" xml:lang="en">quidway-arp-dos(31641)</vuln:reference>
    </vuln:references>
    <vuln:summary>The Huawei Versatile Routing Platform 1.43 2500E-003 firmware on the Quidway R1600 Router, and possibly other models, allows remote attackers to cause a denial of service (device crash) via a long show arp command.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0489">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:visohotlink:visohotlink:1.01"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:visohotlink:visohotlink:1.01</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0489</vuln:cve-id>
    <vuln:published-datetime>2007-01-24T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:59.787-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22171" xml:lang="en">22171</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0285" xml:lang="en">ADV-2007-0285</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31654" xml:lang="en">visohotlink-functions-file-include(31654)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3175" xml:lang="en">3175</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in includes/functions.visohotlink.php in VisoHotlink 1.01 and possibly earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0490">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:open-realty:open-realty:2.3.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:open-realty:open-realty:2.3.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0490</vuln:cve-id>
    <vuln:published-datetime>2007-01-24T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:32:59.917-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457676/100/0/threaded" xml:lang="en">20070121 Full Path Disclosure in Open-Realty ( v2.3.4 )</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31657" xml:lang="en">openrealty-index-path-disclosure(31657)</vuln:reference>
    </vuln:references>
    <vuln:summary>index.php in Open-Realty 2.3.4 allows remote attackers to obtain sensitive information (the full path) via an invalid listingID parameter in a listingview action.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0491">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sky_gunning:myspeach:3.0.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sky_gunning:myspeach:3.0.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0491</vuln:cve-id>
    <vuln:published-datetime>2007-01-24T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:56.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0269" xml:lang="en">ADV-2007-0269</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in up.php in Sky GUNNING MySpeach 3.0.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the my_ms[root] parameter, a different vector than CVE-2006-4630.  NOTE: Some of these details are obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0492">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:webspell:webspell:4.01.02"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:webspell:webspell:4.01.02</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0492</vuln:cve-id>
    <vuln:published-datetime>2007-01-24T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:13.733-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0270" xml:lang="en">ADV-2007-0270</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31632" xml:lang="en">webspell-gallery-sql-injection(31632)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in gallery.php in webSPELL 4.01.02 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) galleryID parameter.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0493">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:isc:bind:9.3.0</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.3.1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.3.2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.0</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.0:rc1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0493</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:27:01.687-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9614" name="oval:org.mitre.oval:def:9614"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305530" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305530</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2507" xml:lang="en">FEDORA-2007-147</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2537" xml:lang="en">FEDORA-2007-164</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NETBSD</vuln:source>
      <vuln:reference href="http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2007-003.txt.asc" xml:lang="en">NetBSD-SA2007-003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01070495" xml:lang="en">SSRT061273</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2007/May/msg00004.html" xml:lang="en">APPLE-SA-2007-05-24</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/052018.html" xml:lang="en">20070125 BIND remote exploit (low severity) [Fwd: Internet Systems Consortium Security Advisory.]</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0016.html" xml:lang="en">SUSE-SA:2007:014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://marc.info/?l=bind-announce&amp;m=116968519321296&amp;w=2" xml:lang="en">[bind-announce] 20070125 Internet Systems Consortium Security Advisory.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FREEBSD</vuln:source>
      <vuln:reference href="http://security.freebsd.org/advisories/FreeBSD-SA-07:02.bind.asc" xml:lang="en">FreeBSD-SA-07:02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200702-06.xml" xml:lang="en">GLSA-200702-06</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017561" xml:lang="en">1017561</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.494157" xml:lang="en">SSA:2007-026-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.isc.org/index.pl?/sw/bind/bind-security.php" xml:lang="en">http://www.isc.org/index.pl?/sw/bind/bind-security.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.isc.org/index.pl?/sw/bind/view/?release=9.2.8" xml:lang="en">http://www.isc.org/index.pl?/sw/bind/view/?release=9.2.8</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.isc.org/index.pl?/sw/bind/view/?release=9.3.4" xml:lang="en">http://www.isc.org/index.pl?/sw/bind/view/?release=9.3.4</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:030" xml:lang="en">MDKSA-2007:030</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OPENPKG</vuln:source>
      <vuln:reference href="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.007.html" xml:lang="en">OpenPKG-SA-2007.007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0057.html" xml:lang="en">RHSA-2007:0057</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458066/100/0/threaded" xml:lang="en">20070125 BIND remote exploit (low severity) [Fwd: Internet Systems Consortium Security Advisory.]</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22229" xml:lang="en">22229</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2007/0005" xml:lang="en">2007-0005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-418-1" xml:lang="en">USN-418-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0349" xml:lang="en">ADV-2007-0349</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1401" xml:lang="en">ADV-2007-1401</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1939" xml:lang="en">ADV-2007-1939</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2163" xml:lang="en">ADV-2007-2163</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2315" xml:lang="en">ADV-2007-2315</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952488" xml:lang="en">https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952488</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-989" xml:lang="en">https://issues.rpath.com/browse/RPL-989</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144" xml:lang="en">SSRT071304</vuln:reference>
    </vuln:references>
    <vuln:summary>Use-after-free vulnerability in ISC BIND 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (named daemon crash) via unspecified vectors that cause named to "dereference a freed fetch context."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0494">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.0.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.0.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.0.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.0.0:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.0.0:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.0.0:rc6"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.0.1:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.0.1:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.1.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.1.1:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.1.1:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.1.1:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.1.1:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.1.1:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.1.1:rc6"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.1.1:rc7"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.1.2:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.1.3:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.1.3:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.1.3:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.0:a1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.0:a2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.0:a3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.0:b1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.0:b2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.0:rc10"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.0:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.0:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.0:rc6"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.0:rc7"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.0:rc8"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.0:rc9"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.1:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.1:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.2:p2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.2:p3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.2:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.3:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.3:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.3:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.3:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.4:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.4:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.4:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.4:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.4:rc6"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.4:rc7"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.4:rc8"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.5:b2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.5:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.2.6:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.3.0:b2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.3.0:b3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.3.0:b4"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.3.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.3.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.3.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.3.0:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.3.1:b2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.3.1:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.3.2:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0:a1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0:a2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0:a3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0:a4"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0:a5"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0:b1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0:b2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0:b3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.5.0:a1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:isc:bind:9.0</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.0.0:rc1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.0.0:rc2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.0.0:rc3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.0.0:rc4</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.0.0:rc5</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.0.0:rc6</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.0.1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.0.1:rc1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.0.1:rc2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.1.0:rc1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.1.1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.1.1:rc1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.1.1:rc2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.1.1:rc3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.1.1:rc4</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.1.1:rc5</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.1.1:rc6</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.1.1:rc7</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.1.2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.1.2:rc1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.1.3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.1.3:rc1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.1.3:rc2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.1.3:rc3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.0</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.0:a1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.0:a2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.0:a3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.0:b1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.0:b2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.0:rc1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.0:rc10</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.0:rc2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.0:rc3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.0:rc4</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.0:rc5</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.0:rc6</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.0:rc7</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.0:rc8</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.0:rc9</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.1:rc1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.1:rc2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.2:p2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.2:p3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.2:rc1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.3:rc1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.3:rc2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.3:rc3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.3:rc4</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.4</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.4:rc2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.4:rc3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.4:rc4</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.4:rc5</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.4:rc6</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.4:rc7</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.4:rc8</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.5</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.5:b2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.5:rc1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.6</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.2.6:rc1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.3.0</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.3.0:b2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.3.0:b3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.3.0:b4</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.3.0:rc1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.3.0:rc2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.3.0:rc3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.3.0:rc4</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.3.1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.3.1:b2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.3.1:rc1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.3.2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.3.2:rc1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.0:a1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.0:a2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.0:a3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.0:a4</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.0:a5</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.0:b1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.0:b2</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.0:b3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.4.0:rc1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:9.5.0:a1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0494</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:37.750-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11523" name="oval:org.mitre.oval:def:11523"/>
    <vuln:cwe id="CWE-19"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc" xml:lang="en">20070201-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305530" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305530</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2507" xml:lang="en">FEDORA-2007-147</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2537" xml:lang="en">FEDORA-2007-164</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NETBSD</vuln:source>
      <vuln:reference href="http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2007-003.txt.asc" xml:lang="en">NetBSD-SA2007-003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01070495" xml:lang="en">SSRT061273</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2007/May/msg00004.html" xml:lang="en">APPLE-SA-2007-05-24</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html" xml:lang="en">20070920 VMSA-2007-0006 Critical security updates for all supported versions of VMware ESX Server, VMware Server, VMware Workstation, VMware ACE, and VMware Player</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0016.html" xml:lang="en">SUSE-SA:2007:014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://marc.info/?l=bind-announce&amp;m=116968519300764&amp;w=2" xml:lang="en">[bind-announce] 20070125 Internet Systems Consortium Security Advisory.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FREEBSD</vuln:source>
      <vuln:reference href="http://security.freebsd.org/advisories/FreeBSD-SA-07:02.bind.asc" xml:lang="en">FreeBSD-SA-07:02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200702-06.xml" xml:lang="en">GLSA-200702-06</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017573" xml:lang="en">1017573</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.494157" xml:lang="en">SSA:2007-026-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102969-1" xml:lang="en">102969</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2007-125.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2007-125.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1254" xml:lang="en">DSA-1254</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.isc.org/index.pl?/sw/bind/bind-security.php" xml:lang="en">http://www.isc.org/index.pl?/sw/bind/bind-security.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.isc.org/index.pl?/sw/bind/view/?release=9.2.8" xml:lang="en">http://www.isc.org/index.pl?/sw/bind/view/?release=9.2.8</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.isc.org/index.pl?/sw/bind/view/?release=9.3.4" xml:lang="en">http://www.isc.org/index.pl?/sw/bind/view/?release=9.3.4</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:030" xml:lang="en">MDKSA-2007:030</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OPENPKG</vuln:source>
      <vuln:reference href="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.007.html" xml:lang="en">OpenPKG-SA-2007.007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0044.html" xml:lang="en">RHSA-2007:0044</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0057.html" xml:lang="en">RHSA-2007:0057</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22231" xml:lang="en">22231</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2007/0005" xml:lang="en">2007-0005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-418-1" xml:lang="en">USN-418-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1401" xml:lang="en">ADV-2007-1401</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1939" xml:lang="en">ADV-2007-1939</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2002" xml:lang="en">ADV-2007-2002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2163" xml:lang="en">ADV-2007-2163</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2245" xml:lang="en">ADV-2007-2245</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2315" xml:lang="en">ADV-2007-2315</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/3229" xml:lang="en">ADV-2007-3229</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?uid=isg1IY95618" xml:lang="en">IY95618</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?uid=isg1IY95619" xml:lang="en">IY95619</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?uid=isg1IY96144" xml:lang="en">IY96144</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?uid=isg1IY96324" xml:lang="en">IY96324</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31838" xml:lang="en">bind-rrsets-dos(31838)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952488" xml:lang="en">https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952488</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-989" xml:lang="en">https://issues.rpath.com/browse/RPL-989</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144" xml:lang="en">SSRT071304</vuln:reference>
    </vuln:references>
    <vuln:summary>ISC BIND 9.0.x, 9.1.x, 9.2.0 up to 9.2.7, 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (exit) via a type * (ANY) DNS query response that contains multiple RRsets, which triggers an assertion error, aka the "DNSSEC Validation" vulnerability.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0495">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpsherpa:phpsherpa"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpsherpa:phpsherpa</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0495</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:59.830-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0263" xml:lang="en">ADV-2007-0263</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3161" xml:lang="en">3161</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in include/config.inc.php in PhpSherpa allows remote attackers to execute arbitrary PHP code via a URL in the racine parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0496">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:neon_labs:neon_labs_website:3.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:neon_labs:neon_labs_website:3.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0496</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:59.877-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0268" xml:lang="en">ADV-2007-0268</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3163" xml:lang="en">3163</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in lib/nl/nl.php in Neon Labs Website (nlws) 3.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the g_strRootDir parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0497">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:upload-service:upload-service:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:upload-service:upload-service:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0497</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:05.590-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://echo.or.id/adv/adv62-y3dips-2007.txt" xml:lang="en">http://echo.or.id/adv/adv62-y3dips-2007.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457800/100/100/threaded" xml:lang="en">20070123 [ECHO_ADV_62$2007] Upload Service 1.0 remote file inclusion</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22189" xml:lang="en">22189</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0265" xml:lang="en">ADV-2007-0265</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31634" xml:lang="en">uploadservice-top-file-include(31634)</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in upload/top.php in Upload-Service 1.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the maindir parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0498">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sky_gunning:myspeach:2.1_beta"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sky_gunning:myspeach:2.1_beta</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0498</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:29:59.927-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3165" xml:lang="en">3165</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in up.php in MySpeach 2.1 beta and possibly earlier allows remote attackers to execute arbitrary PHP code via a URL in the my[root] parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0499">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sangwan_kim:phpindexpage:1.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sangwan_kim:phpindexpage:1.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0499</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:00.003-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22161" xml:lang="en">22161</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0267" xml:lang="en">ADV-2007-0267</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3164" xml:lang="en">3164</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in config.php in Sangwan Kim phpIndexPage 1.0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the env[inc_path] parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0500">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bradabra:bradabra:2.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bradabra:bradabra:2.0.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0500</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:00.067-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0264" xml:lang="en">ADV-2007-0264</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3162" xml:lang="en">3162</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in include/includes.php in Bradabra 2.0.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0501">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mafia_scum_tools:mafia_scum_tools:2.0.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mafia_scum_tools:mafia_scum_tools:2.0.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0501</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:00.127-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22151" xml:lang="en">22151</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0271" xml:lang="en">ADV-2007-0271</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31637" xml:lang="en">mafiascum-index-file-include(31637)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3171" xml:lang="en">3171</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in index.php in Mafia Scum Tools 2.0.0 in Matthew Wardrop Advanced Random Generators (adv-random-gen) allows remote attackers to execute arbitrary PHP code via a URL in the gen parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0502">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:webspell:webspell:4.01.02"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:webspell:webspell:4.01.02</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0502</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:00.177-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22149" xml:lang="en">22149</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0270" xml:lang="en">ADV-2007-0270</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31632" xml:lang="en">webspell-gallery-sql-injection(31632)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3172" xml:lang="en">3172</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in gallery.php in webSPELL 4.01.02 allows remote attackers to execute arbitrary SQL commands via the picID parameter, a different vector than CVE-2007-0492.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0503">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0503</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:37.090-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1495" name="oval:org.mitre.oval:def:1495"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017541" xml:lang="en">1017541</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102728-1" xml:lang="en">102728</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2007-040.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2007-040.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22175" xml:lang="en">22175</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0287" xml:lang="en">ADV-2007-0287</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31668" xml:lang="en">solaris-kcmscalibrate-privilege-escalation(31668)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in kcms_calibrate in Sun Solaris 8 and 9 before 20071122 allows local users to execute arbitrary commands via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0504">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:vote_pro:vote_pro:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vote_pro:vote_pro:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0504</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:00.237-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0300" xml:lang="en">ADV-2007-0300</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3180" xml:lang="en">3180</vuln:reference>
    </vuln:references>
    <vuln:summary>Eval injection vulnerability in poll_frame.php in Vote! Pro 4.0, and possibly other scripts, allows remote attackers to execute arbitrary code via the poll_id parameter, which is supplied to an eval function call, a different vulnerability type than CVE-2005-4632.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0505">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:drupal:project:4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:project:4.6_1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:project:4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:project:4.7_1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:project:4.7_2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:project:5.0::dev"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:project_issue_tracking_module:4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:project_issue_tracking_module:4.7_1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:project_issue_tracking_module:4.7_2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:project_issue_tracking_module:5.0::dev"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:drupal:project:4.6</vuln:product>
      <vuln:product>cpe:/a:drupal:project:4.6_1.1</vuln:product>
      <vuln:product>cpe:/a:drupal:project:4.7</vuln:product>
      <vuln:product>cpe:/a:drupal:project:4.7_1.1</vuln:product>
      <vuln:product>cpe:/a:drupal:project:4.7_2.1</vuln:product>
      <vuln:product>cpe:/a:drupal:project:5.0::dev</vuln:product>
      <vuln:product>cpe:/a:drupal:project_issue_tracking_module:4.7</vuln:product>
      <vuln:product>cpe:/a:drupal:project_issue_tracking_module:4.7_1.1</vuln:product>
      <vuln:product>cpe:/a:drupal:project_issue_tracking_module:4.7_2.1</vuln:product>
      <vuln:product>cpe:/a:drupal:project_issue_tracking_module:5.0::dev</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0505</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:14.127-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>8.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://drupal.org/node/112146" xml:lang="en">http://drupal.org/node/112146</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22224" xml:lang="en">22224</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0312" xml:lang="en">ADV-2007-0312</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31729" xml:lang="en">projecttracking-extension-file-upload(31729)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unrestricted file upload vulnerability in the Project issue tracking 4.7.0 through 5.x before 20070123, a module for Drupal, allows remote authenticated users to execute arbitrary code by attaching a file with executable or multiple extensions to a project issue.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0506">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:drupal:project:4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:project:4.6_1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:project:4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:project:4.7_1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:project:4.7_2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:project:5.0::dev"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:project_issue_tracking_module:4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:project_issue_tracking_module:4.7_1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:project_issue_tracking_module:4.7_2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:project_issue_tracking_module:5.0::dev"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:drupal:project:4.6</vuln:product>
      <vuln:product>cpe:/a:drupal:project:4.6_1.1</vuln:product>
      <vuln:product>cpe:/a:drupal:project:4.7</vuln:product>
      <vuln:product>cpe:/a:drupal:project:4.7_1.1</vuln:product>
      <vuln:product>cpe:/a:drupal:project:4.7_2.1</vuln:product>
      <vuln:product>cpe:/a:drupal:project:5.0::dev</vuln:product>
      <vuln:product>cpe:/a:drupal:project_issue_tracking_module:4.7</vuln:product>
      <vuln:product>cpe:/a:drupal:project_issue_tracking_module:4.7_1.1</vuln:product>
      <vuln:product>cpe:/a:drupal:project_issue_tracking_module:4.7_2.1</vuln:product>
      <vuln:product>cpe:/a:drupal:project_issue_tracking_module:5.0::dev</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0506</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:14.203-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://drupal.org/node/112146" xml:lang="en">http://drupal.org/node/112146</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22224" xml:lang="en">22224</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0312" xml:lang="en">ADV-2007-0312</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31727" xml:lang="en">projecttracking-access-info-disclosure(31727)</vuln:reference>
    </vuln:references>
    <vuln:summary>The project_issue_access function in the Project issue tracking 4.7.0 through 5.x before 20070123 module for Drupal allows remote authenticated users to bypass other access control modules and obtain attached files by guessing the filename, and obtain issue information via direct requests.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0507">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:drupal:acidfree:4.6_1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:acidfree:4.7_1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:drupal:acidfree:4.6_1.0</vuln:product>
      <vuln:product>cpe:/a:drupal:acidfree:4.7_1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0507</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:14.250-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://drupal.org/node/112145" xml:lang="en">http://drupal.org/node/112145</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22202" xml:lang="en">22202</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0313" xml:lang="en">ADV-2007-0313</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31724" xml:lang="en">acidfree-albums-sql-injection(31724)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in the Acidfree module for Drupal before 4.6.x-1.0, and before 4.7.x-1.0 in the 4.7 series, allows remote authenticated users with "create acidfree albums" privileges to execute arbitrary SQL commands via node titles.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0508">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bbclone:bbclone:0.31"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bbclone:bbclone:0.31</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0508</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:00.300-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0318" xml:lang="en">ADV-2007-0318</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3183" xml:lang="en">3183</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in lib/selectlang.php in BBClone 0.31 allows remote attackers to execute arbitrary PHP code via a URL in the BBC_LANGUAGE_PATH parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0509">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:maklerplus:maklerplus:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:maklerplus:maklerplus:1.01"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:maklerplus:maklerplus:1.0</vuln:product>
      <vuln:product>cpe:/a:maklerplus:maklerplus:1.01</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0509</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:14.297-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=479940" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=479940</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22206" xml:lang="en">22206</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0321" xml:lang="en">ADV-2007-0321</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31734" xml:lang="en">maklerplus-multiple-unspecified(31734)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple unspecified vulnerabilities in MaklerPlus before 1.2 have unknown impact and attack vectors, possibly relating to cross-site scripting (XSS) in the slogan parameter in main.tpl, or information leaks in error messages.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0510">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:awffull:awffull:3.7.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:awffull:awffull:3.7.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0510</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:14.360-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.stedee.id.au/awffull#changes" xml:lang="en">http://www.stedee.id.au/awffull#changes</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.stedee.id.au/pipermail/awffull_stedee.id.au/2007-January/000309.html" xml:lang="en">[AWFFULL] 20070123 Regarding the fixes in 3.7.2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0320" xml:lang="en">ADV-2007-0320</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31731" xml:lang="en">awffull-multiple-bo(31731)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in (1) graphs.c, (2) output.c, and (3) preserve.c in AWFFull 3.7.1 and earlier have unknown impact and attack vectors.  NOTE: some of these details are obtained from third party information.  NOTE: There may not be any attack vector that crosses privilege boundaries.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0511">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpxmldom:phpxmldom:0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpxmldom:phpxmldom:0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0511</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:00.363-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22201" xml:lang="en">22201</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0309" xml:lang="en">ADV-2007-0309</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31726" xml:lang="en">phpxd-path-file-include(31726)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3184" xml:lang="en">3184</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple PHP remote file inclusion vulnerabilities in phpXMLDOM (phpXD) 0.3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) dom.php, (2) dtd.php, or (3) parser.php in include/.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0512">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:hitachi:tpi_link:03_04"/>
        <cpe-lang:fact-ref name="cpe:/a:hitachi:tpi_link:03_06_k"/>
        <cpe-lang:fact-ref name="cpe:/a:hitachi:tpi_link:05_00"/>
        <cpe-lang:fact-ref name="cpe:/a:hitachi:tpi_link:05_03_f"/>
        <cpe-lang:fact-ref name="cpe:/a:hitachi:tpi_server_base:03_01"/>
        <cpe-lang:fact-ref name="cpe:/a:hitachi:tpi_server_base:03_01_db"/>
        <cpe-lang:fact-ref name="cpe:/a:hitachi:tpi_server_base:03_01_e"/>
        <cpe-lang:fact-ref name="cpe:/a:hitachi:tpi_server_base:03_01_fd"/>
        <cpe-lang:fact-ref name="cpe:/a:hitachi:tpi_server_base:05_00_h"/>
        <cpe-lang:fact-ref name="cpe:/a:hitachi:tpi_server_base:05_03"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hitachi:tpi_link:03_04</vuln:product>
      <vuln:product>cpe:/a:hitachi:tpi_link:03_06_k</vuln:product>
      <vuln:product>cpe:/a:hitachi:tpi_link:05_00</vuln:product>
      <vuln:product>cpe:/a:hitachi:tpi_link:05_03_f</vuln:product>
      <vuln:product>cpe:/a:hitachi:tpi_server_base:03_01</vuln:product>
      <vuln:product>cpe:/a:hitachi:tpi_server_base:03_01_db</vuln:product>
      <vuln:product>cpe:/a:hitachi:tpi_server_base:03_01_e</vuln:product>
      <vuln:product>cpe:/a:hitachi:tpi_server_base:03_01_fd</vuln:product>
      <vuln:product>cpe:/a:hitachi:tpi_server_base:05_00_h</vuln:product>
      <vuln:product>cpe:/a:hitachi:tpi_server_base:05_03</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0512</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:59.237-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.hitachi-support.com/security_e/vuls_e/HS06-021_e/01-e.html" xml:lang="en">http://www.hitachi-support.com/security_e/vuls_e/HS06-021_e/01-e.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22223" xml:lang="en">22223</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0325" xml:lang="en">ADV-2007-0325</vuln:reference>
    </vuln:references>
    <vuln:summary>Hitachi TP1/LiNK 05-00 through 05-03-/F, 03-04 through 03-06-/K, and 03-00 through 03-03-/H; and TP1/Server Base 05-00 through 05-00-/M, 03-01-E through 03-01-FD, 03-01 through 03-01-DB, and 05-03; allow attackers to cause a denial of service (process crash) via invalid data to an OpenTP1 port.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0513">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:hitachi:hirdb_parallel_server:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:hitachi:hirdb_parallel_server:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:hitachi:hirdb_parallel_server:6"/>
        <cpe-lang:fact-ref name="cpe:/a:hitachi:hirdb_parallel_server:7"/>
        <cpe-lang:fact-ref name="cpe:/a:hitachi:hirdb_single_server:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:hitachi:hirdb_single_server:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:hitachi:hirdb_single_server:6"/>
        <cpe-lang:fact-ref name="cpe:/a:hitachi:hirdb_single_server:7"/>
        <cpe-lang:fact-ref name="cpe:/a:hitachi:hirdb_single_server_workgroup_edition:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:hitachi:hirdb_workgroup_server:6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:hitachi:hirdb_datareplicator:5.0"/>
        <cpe-lang:fact-ref name="cpe:/h:hitachi:hirdb_datareplicator:5.0_64"/>
        <cpe-lang:fact-ref name="cpe:/h:hitachi:hirdb_datareplicator:6"/>
        <cpe-lang:fact-ref name="cpe:/h:hitachi:hirdb_datareplicator:6_64"/>
        <cpe-lang:fact-ref name="cpe:/h:hitachi:hirdb_datareplicator:7"/>
        <cpe-lang:fact-ref name="cpe:/h:hitachi:hirdb_datareplicator:7_64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hitachi:hirdb_parallel_server:4.0</vuln:product>
      <vuln:product>cpe:/a:hitachi:hirdb_parallel_server:5.0</vuln:product>
      <vuln:product>cpe:/a:hitachi:hirdb_parallel_server:6</vuln:product>
      <vuln:product>cpe:/a:hitachi:hirdb_parallel_server:7</vuln:product>
      <vuln:product>cpe:/a:hitachi:hirdb_single_server:4.0</vuln:product>
      <vuln:product>cpe:/a:hitachi:hirdb_single_server:5.0</vuln:product>
      <vuln:product>cpe:/a:hitachi:hirdb_single_server:6</vuln:product>
      <vuln:product>cpe:/a:hitachi:hirdb_single_server:7</vuln:product>
      <vuln:product>cpe:/a:hitachi:hirdb_single_server_workgroup_edition:5.0</vuln:product>
      <vuln:product>cpe:/a:hitachi:hirdb_workgroup_server:6</vuln:product>
      <vuln:product>cpe:/h:hitachi:hirdb_datareplicator:5.0</vuln:product>
      <vuln:product>cpe:/h:hitachi:hirdb_datareplicator:5.0_64</vuln:product>
      <vuln:product>cpe:/h:hitachi:hirdb_datareplicator:6</vuln:product>
      <vuln:product>cpe:/h:hitachi:hirdb_datareplicator:6_64</vuln:product>
      <vuln:product>cpe:/h:hitachi:hirdb_datareplicator:7</vuln:product>
      <vuln:product>cpe:/h:hitachi:hirdb_datareplicator:7_64</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0513</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:14.470-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.hitachi-support.com/security_e/vuls_e/HS06-023_e/01-e.html" xml:lang="en">http://www.hitachi-support.com/security_e/vuls_e/HS06-023_e/01-e.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22244" xml:lang="en">22244</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0327" xml:lang="en">ADV-2007-0327</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31735" xml:lang="en">hitachi-hirdb-request-dos(31735)</vuln:reference>
    </vuln:references>
    <vuln:summary>Hitachi HiRDB Datareplicator 7HiRDB, 7(64), 6, 6(64), 5.0, and 5.0(64); and various products that bundle HiRDB Datareplicator; allows attackers to cause a denial of service (CPU consumption) via certain data.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0514">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:hitachi:cosminexus_application_server"/>
        <cpe-lang:fact-ref name="cpe:/a:hitachi:cosminexus_application_server:6::enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:hitachi:cosminexus_application_server_version_5"/>
        <cpe-lang:fact-ref name="cpe:/a:hitachi:cosminexus_developer_light_version_6"/>
        <cpe-lang:fact-ref name="cpe:/a:hitachi:cosminexus_developer_professional_version_6"/>
        <cpe-lang:fact-ref name="cpe:/a:hitachi:cosminexus_developer_standard_version_6"/>
        <cpe-lang:fact-ref name="cpe:/a:hitachi:cosminexus_developer_version_5"/>
        <cpe-lang:fact-ref name="cpe:/a:hitachi:cosminexus_server_-_enterprise_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:hitachi:cosminexus_server_-_standard_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:hitachi:cosminexus_server_-_standard_edition_version_4"/>
        <cpe-lang:fact-ref name="cpe:/a:hitachi:cosminexus_server_-_web_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:hitachi:cosminexus_server_-_web_edition_version_4"/>
        <cpe-lang:fact-ref name="cpe:/a:hitachi:hitachi_web_server"/>
        <cpe-lang:fact-ref name="cpe:/a:hitachi:ucosminexus_application_server_enterprise:::enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:hitachi:ucosminexus_application_server_smart_edition"/>
        <cpe-lang:fact-ref name="cpe:/a:hitachi:ucosminexus_application_server_standard"/>
        <cpe-lang:fact-ref name="cpe:/a:hitachi:ucosminexus_developer_light"/>
        <cpe-lang:fact-ref name="cpe:/a:hitachi:ucosminexus_developer_standard"/>
        <cpe-lang:fact-ref name="cpe:/a:hitachi:ucosminexus_service_architect"/>
        <cpe-lang:fact-ref name="cpe:/a:hitachi:ucosminexus_service_platform"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hitachi:cosminexus_application_server</vuln:product>
      <vuln:product>cpe:/a:hitachi:cosminexus_application_server:6::enterprise</vuln:product>
      <vuln:product>cpe:/a:hitachi:cosminexus_application_server_version_5</vuln:product>
      <vuln:product>cpe:/a:hitachi:cosminexus_developer_light_version_6</vuln:product>
      <vuln:product>cpe:/a:hitachi:cosminexus_developer_professional_version_6</vuln:product>
      <vuln:product>cpe:/a:hitachi:cosminexus_developer_standard_version_6</vuln:product>
      <vuln:product>cpe:/a:hitachi:cosminexus_developer_version_5</vuln:product>
      <vuln:product>cpe:/a:hitachi:cosminexus_server_-_enterprise_edition</vuln:product>
      <vuln:product>cpe:/a:hitachi:cosminexus_server_-_standard_edition</vuln:product>
      <vuln:product>cpe:/a:hitachi:cosminexus_server_-_standard_edition_version_4</vuln:product>
      <vuln:product>cpe:/a:hitachi:cosminexus_server_-_web_edition</vuln:product>
      <vuln:product>cpe:/a:hitachi:cosminexus_server_-_web_edition_version_4</vuln:product>
      <vuln:product>cpe:/a:hitachi:hitachi_web_server</vuln:product>
      <vuln:product>cpe:/a:hitachi:ucosminexus_application_server_enterprise:::enterprise</vuln:product>
      <vuln:product>cpe:/a:hitachi:ucosminexus_application_server_smart_edition</vuln:product>
      <vuln:product>cpe:/a:hitachi:ucosminexus_application_server_standard</vuln:product>
      <vuln:product>cpe:/a:hitachi:ucosminexus_developer_light</vuln:product>
      <vuln:product>cpe:/a:hitachi:ucosminexus_developer_standard</vuln:product>
      <vuln:product>cpe:/a:hitachi:ucosminexus_service_architect</vuln:product>
      <vuln:product>cpe:/a:hitachi:ucosminexus_service_platform</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0514</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:49:59.453-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.hitachi-support.com/security_e/vuls_e/HS06-022_e/01-e.html" xml:lang="en">http://www.hitachi-support.com/security_e/vuls_e/HS06-022_e/01-e.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0326" xml:lang="en">ADV-2007-0326</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in multiple Hitachi Web Server, uCosminexus, and Cosminexus products before 20070124 allow remote attackers to inject arbitrary web script or HTML via (1) HTTP Expect headers or (2) image maps.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0515">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2004::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word_viewer:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2004"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2005"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2006"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2004::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:word_viewer:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2004</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2005</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2006</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0515</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:42:43.643-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A528" name="oval:org.mitre.oval:def:528"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://isc.sans.org/diary.html?storyid=2133" xml:lang="en">http://isc.sans.org/diary.html?storyid=2133</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017564" xml:lang="en">1017564</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/412225" xml:lang="en">VU#412225</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/advisory/932114.mspx" xml:lang="en">http://www.microsoft.com/technet/security/advisory/932114.mspx</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22225" xml:lang="en">22225</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22328" xml:lang="en">22328</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.symantec.com/enterprise/security_response/weblog/2007/01/multiple_organizations_targett.html" xml:lang="en">http://www.symantec.com/enterprise/security_response/weblog/2007/01/multiple_organizations_targett.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.symantec.com/enterprise/security_response/weblog/2007/01/new_microsoft_word_2000_vulner.html" xml:lang="en">http://www.symantec.com/enterprise/security_response/weblog/2007/01/new_microsoft_word_2000_vulner.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2007-013010-5422-99&amp;tabid=2" xml:lang="en">http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2007-013010-5422-99&amp;tabid=2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" xml:lang="en">TA07-044A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0350" xml:lang="en">ADV-2007-0350</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-014" xml:lang="en">MS07-014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31834" xml:lang="en">word-document-code-execution(31834)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of service on Word 2003, via unknown attack vectors that trigger memory corruption, as exploited by Trojan.Mdropper.W and later by Trojan.Mdropper.X, a different issue than CVE-2006-6456, CVE-2006-5994, and CVE-2006-6561.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0516">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:yana_framework:yana_framework:2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:yana_framework:yana_framework:2.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:yana_framework:yana_framework:2.8.2a"/>
        <cpe-lang:fact-ref name="cpe:/a:yana_framework:yana_framework:2.8.3a"/>
        <cpe-lang:fact-ref name="cpe:/a:yana_framework:yana_framework:2.8.4a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:yana_framework:yana_framework:2.8</vuln:product>
      <vuln:product>cpe:/a:yana_framework:yana_framework:2.8.1</vuln:product>
      <vuln:product>cpe:/a:yana_framework:yana_framework:2.8.2a</vuln:product>
      <vuln:product>cpe:/a:yana_framework:yana_framework:2.8.3a</vuln:product>
      <vuln:product>cpe:/a:yana_framework:yana_framework:2.8.4a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0516</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:14.593-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.9</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://all-community.de/pub/pages/changes.php?language=en" xml:lang="en">http://all-community.de/pub/pages/changes.php?language=en</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31671" xml:lang="en">yana-unspecified-security-bypass(31671)</vuln:reference>
    </vuln:references>
    <vuln:summary>Yana Framework before 2.8.5a allows remote authenticated users with permissions to modify a guestbook profile to modify or delete arbitrary guestbook profiles via unspecified vectors.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0517">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:scriptsez:random_php_quote:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:scriptsez:random_php_quote:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0517</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:06.090-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2184" xml:lang="en">2184</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457825/100/0/threaded" xml:lang="en">20070123 RANDOM PHP QUOTE 1.0 (pwd.txt) Remote Password Disclosur</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31696" xml:lang="en">randomphpquote-pwd-information-disclosure(31696)</vuln:reference>
    </vuln:references>
    <vuln:summary>Scriptsez Random PHP Quote 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain password information via a direct request for pwd.txt.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0518">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:scriptsez:smart_php_subscriber"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:scriptsez:smart_php_subscriber</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0518</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:06.463-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2183" xml:lang="en">2183</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457852/100/0/threaded" xml:lang="en">20070123 subscribe (pwd.txt) Remote Password Disclosur</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31701" xml:lang="en">subscriber-pwd-information-disclosure(31701)</vuln:reference>
    </vuln:references>
    <vuln:summary>Scriptsez Smart PHP Subscriber (aka subscribe) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain encoded passwords via a direct request for pwd.txt.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0519">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:xmb_software:u2u_instant_messenger"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xmb_software:u2u_instant_messenger</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0519</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:06.840-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://aria-security.com/forum/showthread.php?p=129" xml:lang="en">http://aria-security.com/forum/showthread.php?p=129</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2182" xml:lang="en">2182</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457630/100/0/threaded" xml:lang="en">20070120 XMB "U2U Instant Messenger" Cross-Site Scripting</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31661" xml:lang="en">u2u-memcp-xss(31661)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in memcp.php in XMB U2U Instant Messenger allows remote authenticated users to inject arbitrary web script or HTML via the recipient field.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0520">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:unique_ads:unique_ads:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:unique_ads:unique_ads:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0520</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:07.167-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2181" xml:lang="en">2181</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457667/100/0/threaded" xml:lang="en">20070121 SQL Injection in Unique Ads ( UDS )</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31660" xml:lang="en">uniqueads-banner-sql-injection(31660)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in banner.php in Unique Ads (UDS) 1.x allows remote attackers to execute arbitrary SQL commands via the bid parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0521">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:sony_ericsson:k700i"/>
        <cpe-lang:fact-ref name="cpe:/h:sony_ericsson:w810i"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:sony_ericsson:k700i</vuln:product>
      <vuln:product>cpe:/h:sony_ericsson:w810i</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0521</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:07.433-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.3</cvss:score>
        <cvss:access-vector>ADJACENT_NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2180" xml:lang="en">2180</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457768/100/0/threaded" xml:lang="en">20070123 Bluetooth DoS by obex push</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457797/100/0/threaded" xml:lang="en">20070123 Re: Bluetooth DoS by obex push [readable]</vuln:reference>
    </vuln:references>
    <vuln:summary>The Sony Ericsson K700i and W810i phones allow remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a file over Bluetooth, as demonstrated by ussp-push.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0522">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:motorola:motorazr:v3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:motorola:motorazr:v3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0522</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:07.700-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.3</cvss:score>
        <cvss:access-vector>ADJACENT_NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2180" xml:lang="en">2180</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457768/100/0/threaded" xml:lang="en">20070123 Bluetooth DoS by obex push</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457797/100/0/threaded" xml:lang="en">20070123 Re: Bluetooth DoS by obex push [readable]</vuln:reference>
    </vuln:references>
    <vuln:summary>The Motorola MOTORAZR V3 phone allows remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a file over Bluetooth, as demonstrated by ussp-push.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0523">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:nokia:n70"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:nokia:n70</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0523</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:07.967-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.3</cvss:score>
        <cvss:access-vector>ADJACENT_NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2180" xml:lang="en">2180</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457768/100/0/threaded" xml:lang="en">20070123 Bluetooth DoS by obex push</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457797/100/0/threaded" xml:lang="en">20070123 Re: Bluetooth DoS by obex push [readable]</vuln:reference>
    </vuln:references>
    <vuln:summary>The Nokia N70 phone allows remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a file over Bluetooth, as demonstrated by ussp-push.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0524">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:lg_electronics:chocolate_kg800"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:lg_electronics:chocolate_kg800</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0524</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:08.230-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.9</cvss:score>
        <cvss:access-vector>ADJACENT_NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2180" xml:lang="en">2180</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457768/100/0/threaded" xml:lang="en">20070123 Bluetooth DoS by obex push</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457797/100/0/threaded" xml:lang="en">20070123 Re: Bluetooth DoS by obex push [readable]</vuln:reference>
    </vuln:references>
    <vuln:summary>The LG Chocolate KG800 phone allows remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a file over Bluetooth, as demonstrated by ussp-push.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0525">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:grigoriadis:mini_web_server:0.04"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:grigoriadis:mini_web_server:0.04</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0525</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:50:12.610-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=479480&amp;group_id=187000" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=479480&amp;group_id=187000</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0294" xml:lang="en">ADV-2007-0294</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in Nickolas Grigoriadis Mini Web server (MiniWebsvr) before 0.05 have unknown impact and attack vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0526">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bitweaver:bitweaver:1.3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bitweaver:bitweaver:1.3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0526</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:08.480-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2186" xml:lang="en">2186</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457695/100/0/threaded" xml:lang="en">20070122 [x0n3-h4ck] bitweaver 1.3.1 XSS Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31655" xml:lang="en">bitweaver-multiple-scripts-xss(31655)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 1.3.1 allow remote attackers to inject arbitrary web script or HTML via the URL (PATH_INFO) to (1) articles/edit.php, (2) articles/list.php, (3) blogs/list_blogs.php, or (4) blogs/rankings.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0527">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:website_baker:website_baker:2.6.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:website_baker:website_baker:2.6.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0527</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:08.950-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2185" xml:lang="en">2185</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457684/100/0/threaded" xml:lang="en">20070122 SQL Injection by using Cookie Poisoning for Website Baker Version 2.6.5 and before</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22176" xml:lang="en">22176</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0311" xml:lang="en">ADV-2007-0311</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31692" xml:lang="en">websitebaker-login-sql-injection(31692)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in the is_remembered function in class.login.php in Website Baker 2.6.5 and earlier allows remote attackers to execute arbitrary SQL commands via the REMEMBER_KEY cookie parameter. NOTE: some of these details are obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0528">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:centrality_communications:pa168_chipset:firmware_1.54"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:centrality_communications:pa168_chipset:firmware_1.54</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0528</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:09.403-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.procheckup.com/Vulner_PR0614.php" xml:lang="en">http://www.procheckup.com/Vulner_PR0614.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457868/100/0/threaded" xml:lang="en">20070123 PR06-14: IP Phones based on Centrality Communications/Aredfox PA168 chipset weak session management vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0346" xml:lang="en">ADV-2007-0346</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3189" xml:lang="en">3189</vuln:reference>
    </vuln:references>
    <vuln:summary>The admin web console implemented by the Centrality Communications (aka Aredfox) PA168 chipset and firmware 1.54 and earlier, as provided by various IP phones, does not require passwords or authentication tokens when using HTTP, which allows remote attackers to connect to existing superuser sessions and obtain sensitive information (passwords and configuration data).</vuln:summary>
  </entry>
  <entry id="CVE-2007-0529">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:php_link_directory:php_link_directory:3.0.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php_link_directory:php_link_directory:3.0.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0529</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:09.857-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457672/100/0/threaded" xml:lang="en">20070121 PHP Link Directory XSS Vulnerability version &lt;= 3.0.6</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.smilehouse.com/advisory/phplinkdirectory_070121.txt" xml:lang="en">http://www.smilehouse.com/advisory/phplinkdirectory_070121.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31662" xml:lang="en">phpld-admin-xss(31662)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in index.html (aka the administration page) in PHP Link Directory (phpLD) 3.0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted link, which is triggered when the administrator uses the "Validate Links" functionality.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0530">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:advanced_guestbook:advanced_guestbook:2.4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:advanced_guestbook:advanced_guestbook:2.4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0530</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:10.153-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457870/100/0/threaded" xml:lang="en">20070123 Advanced Guestbook &lt;=- 2.4.2 (include_path) Remote File Include Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457955/100/0/threaded" xml:lang="en">20070123 Re: Advanced Guestbook &lt;=- 2.4.2 (include_path) Remote File Include Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>** DISPUTED **  Multiple PHP remote file inclusion vulnerabilities in Advanced Guestbook 2.4.2 allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to (1) index.php, (2) addentry.php, or (3) picture.php, a different set of vectors than CVE-2006-5804.  NOTE: this issue has been disputed by third party researchers, stating that the include_path variable is instantiated before use.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0531">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:freewebshop:freewebshop:2.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:freewebshop:freewebshop:2.2.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:freewebshop:freewebshop:2.2.3</vuln:product>
      <vuln:product>cpe:/a:freewebshop:freewebshop:2.2.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0531</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:15.267-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://14house.blogspot.com/2007/01/freewebshoporg-remote-file-inclusion.html" xml:lang="en">http://14house.blogspot.com/2007/01/freewebshoporg-remote-file-inclusion.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017549" xml:lang="en">1017549</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.freewebshop.org/?id=36" xml:lang="en">http://www.freewebshop.org/?id=36</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0319" xml:lang="en">ADV-2007-0319</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31732" xml:lang="en">freewebshop-login-file-include(31732)</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in includes/login.php in FreeWebShop 2.2.3 and 2.2.4 before 20070123 allows remote attackers to execute arbitrary PHP code via a URL in the lang_file parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0532">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:tuan_do:uploader:6_beta_1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:tuan_do:uploader:6_beta_1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0532</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:10.293-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2187" xml:lang="en">2187</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457698/100/0/threaded" xml:lang="en">20070122 Uploader &lt;= (userdata/user_1.txt) Password Disclosure Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31683" xml:lang="en">uploader-userdata-info-disclosure(31683)</vuln:reference>
    </vuln:references>
    <vuln:summary>Tuan Do Uploader (aka php-uploader) 6 beta 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the administrator password hash via a direct request for userdata/user_1.txt.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0533">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:atozed_software:intraweb_component:8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:atozed_software:intraweb_component:9.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:atozed_software:intraweb_component:8.0</vuln:product>
      <vuln:product>cpe:/a:atozed_software:intraweb_component:9.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0533</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:10.543-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://blogs.atozed.com/Olaf/20070124.en.aspx" xml:lang="en">http://blogs.atozed.com/Olaf/20070124.en.aspx</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://blogs.atozed.com/Olaf/20070124A.en.aspx" xml:lang="en">http://blogs.atozed.com/Olaf/20070124A.en.aspx</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457758/100/0/threaded" xml:lang="en">20070123 AToZed Software Intraweb Component for Borland Delphi and Kylix DoS vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457947/100/0/threaded" xml:lang="en">20070124 Re: AToZed Software Intraweb Component for Borland Delphi and Kylix DoS vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458121/100/0/threaded" xml:lang="en">20070125 Re: AToZed Software Intraweb Component for Borland Delphi and Kylix DoS vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22185" xml:lang="en">22185</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0355" xml:lang="en">ADV-2007-0355</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31685" xml:lang="en">intraweb-component-dos(31685)</vuln:reference>
    </vuln:references>
    <vuln:summary>The AToZed IntraWeb component 8.0 and earlier for Borland Delphi and Kylix, and IntraWeb 9.0 before build (9.0.12), allows remote attackers to cause a denial of service (thread hang or CPU consumption) via a crafted HTTP request, related to the OnBeforeDispatch function in the TIWServerController object.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0534">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:drupal:project:4.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:project:5"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:project_issue_tracking_module:4.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:project_issue_tracking_module:5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:drupal:project:4.6.0</vuln:product>
      <vuln:product>cpe:/a:drupal:project:5</vuln:product>
      <vuln:product>cpe:/a:drupal:project_issue_tracking_module:4.7.0</vuln:product>
      <vuln:product>cpe:/a:drupal:project_issue_tracking_module:5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0534</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:15.423-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://drupal.org/node/112146" xml:lang="en">http://drupal.org/node/112146</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22224" xml:lang="en">22224</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0312" xml:lang="en">ADV-2007-0312</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31728" xml:lang="en">projecttracking-unspecified-xss(31728)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in the (1) Project issue tracking 4.7.0 through 5.x before 20070123 and (2) Project 4.6.0 through 5.x before 20070123 modules for Drupal allow remote authenticated users to inject arbitrary web script or HTML via (a) certain "fields on project nodes" or (b) "certain project-specific settings regarding issue tracking."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0535">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:vote_pro:vote_pro:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vote_pro:vote_pro:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0535</vuln:cve-id>
    <vuln:published-datetime>2007-01-25T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:50:14.237-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0300" xml:lang="en">ADV-2007-0300</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple eval injection vulnerabilities in Vote! Pro 4.0, and possibly earlier, allow remote attackers to execute arbitrary code via requests to unspecified PHP scripts with the poll_id parameter, which is supplied to eval function calls, a different set of vectors than CVE-2007-0504.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0536">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:rpath:rpath_linux:1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:rpath:rpath_linux:1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0536</vuln:cve-id>
    <vuln:published-datetime>2007-01-26T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:15.483-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lists.rpath.com/pipermail/security-announce/2007-January/000137.html" xml:lang="en">http://lists.rpath.com/pipermail/security-announce/2007-January/000137.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31942" xml:lang="en">rpath-rmake-privilege-escalation(31942)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-987" xml:lang="en">https://issues.rpath.com/browse/RPL-987</vuln:reference>
    </vuln:references>
    <vuln:summary>The chroot helper in rMake for rPath Linux 1 does not drop supplemental groups, which causes packages to be installed with insecure permissions and might allow local users to gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0537">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:kde:konqueror:3.5.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kde:konqueror:3.5.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0537</vuln:cve-id>
    <vuln:published-datetime>2007-01-29T11:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:11.247-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10244" name="oval:org.mitre.oval:def:10244"/>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017591" xml:lang="en">1017591</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200703-10.xml" xml:lang="en">GLSA-200703-10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kde.org/info/security/advisory-20070206-1.txt" xml:lang="en">http://www.kde.org/info/security/advisory-20070206-1.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:031" xml:lang="en">MDKSA-2007:031</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:157" xml:lang="en">MDKSA-2007:157</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_6_sr.html" xml:lang="en">SUSE-SR:2007:006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0909.html" xml:lang="en">RHSA-2007:0909</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457924/100/0/threaded" xml:lang="en">20070124 Re: Safari Improperly Parses HTML Documents &amp; BlogSpot XSS vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22428" xml:lang="en">22428</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-420-1" xml:lang="en">USN-420-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0505" xml:lang="en">ADV-2007-0505</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1117" xml:lang="en">https://issues.rpath.com/browse/RPL-1117</vuln:reference>
    </vuln:references>
    <vuln:summary>The KDE HTML library (kdelibs), as used by Konqueror 3.5.5, does not properly parse HTML comments, which allows remote attackers to conduct cross-site scripting (XSS) attacks and bypass some XSS protection schemes by embedding certain HTML tags within a comment in a title tag, a related issue to CVE-2007-0478.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0538">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:telligent_systems:community_server_forums:2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:telligent_systems:community_server_forums:2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0538</vuln:cve-id>
    <vuln:published-datetime>2007-01-29T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:12.700-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2211" xml:lang="en">2211</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457996/100/0/threaded" xml:lang="en">20070124 Weaknesses in Pingback Design</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457999/100/0/threaded" xml:lang="en">20070124 DoS against Telligent Community Server</vuln:reference>
    </vuln:references>
    <vuln:summary>Telligent Community Server 2.1 and earlier allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to (1) a large file, which triggers a long download session without a timeout constraint; or (2) a file with a binary content type, which is downloaded even though it cannot contain usable pingback data.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0539">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0539</vuln:cve-id>
    <vuln:published-datetime>2007-01-29T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:13.043-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2191" xml:lang="en">2191</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457996/100/0/threaded" xml:lang="en">20070124 Weaknesses in Pingback Design</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458003/100/0/threaded" xml:lang="en">20070124 Multiple Remote Vulnerabilities in Wordpress</vuln:reference>
    </vuln:references>
    <vuln:summary>The wp_remote_fopen function in WordPress before 2.1 allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a large file, which triggers a long download session without a timeout constraint.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0540">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0540</vuln:cve-id>
    <vuln:published-datetime>2007-01-29T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:13.293-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2191" xml:lang="en">2191</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2008/dsa-1564" xml:lang="en">DSA-1564</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457996/100/0/threaded" xml:lang="en">20070124 Weaknesses in Pingback Design</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458003/100/0/threaded" xml:lang="en">20070124 Multiple Remote Vulnerabilities in Wordpress</vuln:reference>
    </vuln:references>
    <vuln:summary>WordPress allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a file with a binary content type, which is downloaded even though it cannot contain usable pingback data.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0541">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0541</vuln:cve-id>
    <vuln:published-datetime>2007-01-29T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:13.637-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2191" xml:lang="en">2191</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457996/100/0/threaded" xml:lang="en">20070124 Weaknesses in Pingback Design</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458003/100/0/threaded" xml:lang="en">20070124 Multiple Remote Vulnerabilities in Wordpress</vuln:reference>
    </vuln:references>
    <vuln:summary>WordPress allows remote attackers to determine the existence of arbitrary files, and possibly read portions of certain files, via pingback service calls with a source URI that corresponds to a local pathname, which triggers different fault codes for existing and non-existing files, and in certain configurations causes a brief file excerpt to be published as a blog comment.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0542">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:212cafe:guestbook:4.00_beta"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:212cafe:guestbook:4.00_beta</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0542</vuln:cve-id>
    <vuln:published-datetime>2007-01-29T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:13.887-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2190" xml:lang="en">2190</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457660/100/0/threaded" xml:lang="en">20070121 XSS in Guestbook ( v.4.00 beta )</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31663" xml:lang="en">guestbook-show-xss(31663)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in show.php in 212cafe Guestbook 4.00 beta allows remote attackers to inject arbitrary web script or HTML via the user parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0543">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:zixforum:zixforum:1.14"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:zixforum:zixforum:1.14</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0543</vuln:cve-id>
    <vuln:published-datetime>2007-01-29T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:14.120-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2189" xml:lang="en">2189</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457950/100/0/threaded" xml:lang="en">20070124 ZixForum &lt;= 1.14 (Zixforum.mdb) Remote Password Disclosure Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458135/100/100/threaded" xml:lang="en">20070124 Re: ZixForum &lt;= 1.14 (Zixforum.mdb) Remote Password Disclosure Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>ZixForum 1.14 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for Zixforum.mdb.  NOTE: a followup post suggests that this issue only occurs if the administrator does not properly follow installation directions.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0544">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mybb:mybb:1.2.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mybb:mybb:1.2.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0544</vuln:cve-id>
    <vuln:published-datetime>2007-01-29T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:14.403-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457929/100/0/threaded" xml:lang="en">20070124 [Aria-Security Team] MyBB Cross-Site Scripting</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22205" xml:lang="en">22205</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31740" xml:lang="en">mybb-subject-field-xss(31740)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in private.php in MyBB (aka MyBulletinBoard) allows remote authenticated users to inject arbitrary web script or HTML via the Subject field, a different vector than CVE-2006-2949.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0545">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:maxtricity:tagger:0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:maxtricity:tagger:0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0545</vuln:cve-id>
    <vuln:published-datetime>2007-01-29T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:14.903-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2214" xml:lang="en">2214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457953/100/0/threaded" xml:lang="en">20070124 Maxtricity Tagger Password Disclosure Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>Maxtricity Tagger 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for tagger.mdb.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0546">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:toxiclab:shoutbox:1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:toxiclab:shoutbox:1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0546</vuln:cve-id>
    <vuln:published-datetime>2007-01-29T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:15.107-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2213" xml:lang="en">2213</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457931/100/0/threaded" xml:lang="en">20070124 Toxiclab Shoutbox Password Disclosure Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>Toxiclab Shoutbox 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db.mdb.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0547">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cgi-rescue:webform:4.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cgi-rescue:webform:4.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0547</vuln:cve-id>
    <vuln:published-datetime>2007-01-29T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:50:15.500-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>JVN</vuln:source>
      <vuln:reference href="http://jvn.jp/jp/JVN%2305123538/index.html" xml:lang="en">JVN#05123538</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0344" xml:lang="en">ADV-2007-0344</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in CGI-RESCUE WebFORM 4.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0548">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:karjasoft:sami_http_server:2.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:karjasoft:sami_http_server:2.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0548</vuln:cve-id>
    <vuln:published-datetime>2007-01-29T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:00.473-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31690" xml:lang="en">sami-http-request-dos(31690)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3182" xml:lang="en">3182</vuln:reference>
    </vuln:references>
    <vuln:summary>KarjaSoft Sami HTTP Server 2.0.1 allows remote attackers to cause a denial of service (daemon hang) via a large number of requests for nonexistent objects.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0549">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:212cafe:212cafeboard:6.30_beta"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:212cafe:212cafeboard:6.30_beta</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0549</vuln:cve-id>
    <vuln:published-datetime>2007-01-29T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:15.307-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2212" xml:lang="en">2212</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457611/100/0/threaded" xml:lang="en">20070121 XSS in 212cafeBoard ( Verision 0.08 &amp; 6.30 Beta )</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31650" xml:lang="en">212cafeboard-list3-xss(31650)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in list3.php in 212cafeBoard 6.30 Beta allows remote attackers to inject arbitrary web script or HTML via the user parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0550">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:212cafe:212cafeboard:0.08_beta"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:212cafe:212cafeboard:0.08_beta</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0550</vuln:cve-id>
    <vuln:published-datetime>2007-01-29T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:15.527-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2212" xml:lang="en">2212</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457611/100/0/threaded" xml:lang="en">20070121 XSS in 212cafeBoard ( Verision 0.08 &amp; 6.30 Beta )</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31651" xml:lang="en">212cafeboard-search-xss(31651)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in search.php in 212cafeBoard 0.08 Beta allows remote attackers to inject arbitrary web script or HTML via keyword parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0551">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cmsmadesimple:cms_made_simple:2.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cmsmadesimple:cms_made_simple:2.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0551</vuln:cve-id>
    <vuln:published-datetime>2007-01-29T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:15.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2195" xml:lang="en">2195</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/457668/100/0/threaded" xml:lang="en">20070120 cmsimple 2.7 Remote File Include</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31658" xml:lang="en">cmsimple-cms-file-include(31658)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple PHP remote file inclusion vulnerabilities in cmsimple/cms.php in CMSimple 2.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) pth[file][config] and (2) pth[file][image] parameters.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0552">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:oh_no_not_another_cms:oh_no_not_another_cms:0.0.8.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oh_no_not_another_cms:oh_no_not_another_cms:0.0.8.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0552</vuln:cve-id>
    <vuln:published-datetime>2007-01-29T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:15.877-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://onnac.svn.sourceforge.net/viewvc/onnac/trunk/install/default/error404.html?view=log" xml:lang="en">http://onnac.svn.sourceforge.net/viewvc/onnac/trunk/install/default/error404.html?view=log</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/forum/forum.php?forum_id=655260" xml:lang="en">http://sourceforge.net/forum/forum.php?forum_id=655260</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22256" xml:lang="en">22256</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0347" xml:lang="en">ADV-2007-0347</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31795" xml:lang="en">onnac-error-xss(31795)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in install/default/error404.html in Oh no! Not another CMS (Onnac) 0.0.8.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the error_url parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0553">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phproxy:phproxy:0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:phproxy:phproxy:0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:phproxy:phproxy:0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:phproxy:phproxy:0.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phproxy:phproxy:0.1</vuln:product>
      <vuln:product>cpe:/a:phproxy:phproxy:0.2</vuln:product>
      <vuln:product>cpe:/a:phproxy:phproxy:0.3</vuln:product>
      <vuln:product>cpe:/a:phproxy:phproxy:0.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0553</vuln:cve-id>
    <vuln:published-datetime>2007-01-29T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:50:16.110-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=479999&amp;group_id=110693" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=479999&amp;group_id=110693</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22255" xml:lang="en">22255</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0348" xml:lang="en">ADV-2007-0348</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in index.inc.php in PHProxy before 0.5 beta 2 allow remote attackers to inject arbitrary web script or HTML via the (1) data[realm] and (2) _url parameters, different vectors than CVE-2004-2604.  NOTE: some of these details are obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0554">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:guo_xu_guos_posting_system:guo_xu_guos_posting_system:1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:guo_xu_guos_posting_system:guo_xu_guos_posting_system:1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0554</vuln:cve-id>
    <vuln:published-datetime>2007-01-29T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:16.073-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2209" xml:lang="en">2209</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458061/100/0/threaded" xml:lang="en">20070125 GPS 1.2 Content Managing System (print.asp) Remote SQL Injection Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22232" xml:lang="en">22232</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0353" xml:lang="en">ADV-2007-0353</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31759" xml:lang="en">gps-print-sql-injection(31759)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3195" xml:lang="en">3195</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in print.asp in Guo Xu Guos Posting System (GPS) 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0555">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.4"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:postgresql:postgresql:7.3</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.4</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.0</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.1</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0555</vuln:cve-id>
    <vuln:published-datetime>2007-02-05T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:16.683-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>8.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9739" name="oval:org.mitre.oval:def:9739"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc" xml:lang="en">20070201-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2554" xml:lang="en">FEDORA-2007-198</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.rpath.com/pipermail/security-announce/2007-February/000141.html" xml:lang="en">[security-announce] 20070206 rPSA-2007-0025-1 postgresql postgresql-server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200703-15.xml" xml:lang="en">GLSA-200703-15</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017597" xml:lang="en">1017597</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102825-1" xml:lang="en">102825</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2007-117.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2007-117.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1261" xml:lang="en">DSA-1261</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:037" xml:lang="en">MDKSA-2007:037</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_10_sr.html" xml:lang="en">SUSE-SR:2007:010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.postgresql.org/support/security" xml:lang="en">http://www.postgresql.org/support/security</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0064.html" xml:lang="en">RHSA-2007:0064</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0067.html" xml:lang="en">RHSA-2007:0067</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0068.html" xml:lang="en">RHSA-2007:0068</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459280/100/0/threaded" xml:lang="en">20070206 rPSA-2007-0025-1 postgresql postgresql-server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459448/100/0/threaded" xml:lang="en">20070208 rPSA-2007-0025-2 postgresql postgresql-server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22387" xml:lang="en">22387</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2007/0007" xml:lang="en">2007-0007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-417-2" xml:lang="en">USN-417-2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0478" xml:lang="en">ADV-2007-0478</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0774" xml:lang="en">ADV-2007-0774</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32195" xml:lang="en">postgresql-sqlfunctions-info-disclosure(32195)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1025" xml:lang="en">https://issues.rpath.com/browse/RPL-1025</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-830" xml:lang="en">https://issues.rpath.com/browse/RPL-830</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="https://usn.ubuntu.com/417-1/" xml:lang="en">USN-417-1</vuln:reference>
    </vuln:references>
    <vuln:summary>PostgreSQL 7.3 before 7.3.13, 7.4 before 7.4.16, 8.0 before 8.0.11, 8.1 before 8.1.7, and 8.2 before 8.2.2 allows attackers to disable certain checks for the data types of SQL function arguments, which allows remote authenticated users to cause a denial of service (server crash) and possibly access database content.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0556">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:1.01"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:1.02"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:1.09"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:6.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:6.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:6.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:6.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:6.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:6.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:6.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:6.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:6.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.3.12"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.3.13"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.3.14"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.3.15"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.3.16"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.3.17"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.3.18"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.4"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.4.8"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.4.9"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.4.10"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.4.11"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.4.12"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.4.13"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.4.14"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.4.15"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:7.4.16"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.2"/>
        <cpe-lang:fact-ref name="cpe:/a:postgresql:postgresql:8.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:postgresql:postgresql:1.0</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:1.01</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:1.02</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:1.09</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:6.0</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:6.1</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:6.1.1</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:6.2</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:6.2.1</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:6.3</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:6.3.1</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:6.3.2</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:6.4</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:6.4.1</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:6.4.2</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:6.5</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:6.5.1</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:6.5.2</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:6.5.3</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.0</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.0.1</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.0.2</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.0.3</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.1</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.1.1</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.1.2</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.1.3</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.2</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.2.1</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.2.2</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.2.3</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.2.4</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.2.5</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.2.6</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.2.7</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.2.8</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.3</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.3.1</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.3.2</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.3.3</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.3.4</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.3.5</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.3.6</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.3.7</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.3.8</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.3.9</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.3.10</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.3.11</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.3.12</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.3.13</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.3.14</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.3.15</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.3.16</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.3.17</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.3.18</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.4</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.4.1</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.4.2</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.4.3</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.4.4</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.4.5</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.4.6</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.4.7</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.4.8</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.4.9</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.4.10</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.4.11</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.4.12</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.4.13</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.4.14</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.4.15</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:7.4.16</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.0</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.0.1</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.0.2</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.0.3</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.0.4</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.0.5</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.0.6</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.0.7</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.0.8</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.0.9</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.0.10</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.1</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.1.1</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.1.2</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.1.3</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.1.4</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.1.5</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.1.6</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.2</vuln:product>
      <vuln:product>cpe:/a:postgresql:postgresql:8.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0556</vuln:cve-id>
    <vuln:published-datetime>2007-02-05T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:20.590-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11353" name="oval:org.mitre.oval:def:11353"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2554" xml:lang="en">FEDORA-2007-198</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.rpath.com/pipermail/security-announce/2007-February/000141.html" xml:lang="en">[security-announce] 20070206 rPSA-2007-0025-1 postgresql postgresql-server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200703-15.xml" xml:lang="en">GLSA-200703-15</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017597" xml:lang="en">1017597</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102825-1" xml:lang="en">102825</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2007-117.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2007-117.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:037" xml:lang="en">MDKSA-2007:037</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_10_sr.html" xml:lang="en">SUSE-SR:2007:010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.postgresql.org/support/security" xml:lang="en">http://www.postgresql.org/support/security</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0067.html" xml:lang="en">RHSA-2007:0067</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0068.html" xml:lang="en">RHSA-2007:0068</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459280/100/0/threaded" xml:lang="en">20070206 rPSA-2007-0025-1 postgresql postgresql-server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459448/100/0/threaded" xml:lang="en">20070208 rPSA-2007-0025-2 postgresql postgresql-server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22387" xml:lang="en">22387</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2007/0007" xml:lang="en">2007-0007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-417-2" xml:lang="en">USN-417-2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0478" xml:lang="en">ADV-2007-0478</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0774" xml:lang="en">ADV-2007-0774</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32191" xml:lang="en">postgresql-datatype-information-disclosure(32191)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1025" xml:lang="en">https://issues.rpath.com/browse/RPL-1025</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-830" xml:lang="en">https://issues.rpath.com/browse/RPL-830</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="https://usn.ubuntu.com/417-1/" xml:lang="en">USN-417-1</vuln:reference>
    </vuln:references>
    <vuln:summary>The query planner in PostgreSQL before 8.0.11, 8.1 before 8.1.7, and 8.2 before 8.2.2 does not verify that a table is compatible with a "previously made query plan," which allows remote authenticated users to cause a denial of service (server crash) and possibly access database content via an "ALTER COLUMN TYPE" SQL statement, which can be leveraged to read arbitrary memory from the server.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0557">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:rmake:rmake:1.0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rmake:rmake:1.0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0557</vuln:cve-id>
    <vuln:published-datetime>2007-01-29T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:41:02.530-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1002" xml:lang="en">https://issues.rpath.com/browse/RPL-1002</vuln:reference>
    </vuln:references>
    <vuln:summary>rMake before 1.0.4 drops root privileges in a way that retains the original supplemental groups, which might allow attackers to gain privileges via a crafted recipe file, a different vulnerability than CVE-2007-0536.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0558">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:inter7:vhostadmin:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:inter7:vhostadmin:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0558</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T11:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:00.567-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0339" xml:lang="en">ADV-2007-0339</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3191" xml:lang="en">3191</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in modules/mail/main.php in Inter7 vHostAdmin 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the MODULES_DIR parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0559">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:rp_world:rp_world:1.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rp_world:rp_world:1.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0559</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T11:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:00.613-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0342" xml:lang="en">ADV-2007-0342</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3185" xml:lang="en">3185</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in config.php in RPW 1.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the sql_language parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0560">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:asp_edge:asp_edge:1.2b"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:asp_edge:asp_edge:1.2b</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0560</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T11:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:25.090-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458058/100/100/threaded" xml:lang="en">20070125 ASP EDGE &lt;= V1.2b (user.asp) Remote SQL Injection Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22212" xml:lang="en">22212</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0341" xml:lang="en">ADV-2007-0341</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31723" xml:lang="en">aspedge-user-sql-injection(31723)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3186" xml:lang="en">3186</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in user.asp in ASP EDGE 1.2b and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0561">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:xero_portal:xero_portal:1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xero_portal:xero_portal:1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0561</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T11:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:25.683-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458059/100/0/threaded" xml:lang="en">20070125 Xero Portal v1.2 (phpbb_root_path) Remote File Include Vulnerablity</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22227" xml:lang="en">22227</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0338" xml:lang="en">ADV-2007-0338</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31767" xml:lang="en">xero-multiple-scripts-file-include(31767)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3192" xml:lang="en">3192</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple PHP remote file inclusion vulnerabilities in Xero Portal 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) admin_linkdb.php, (2) admin_forum_prune.php, (3) admin_extensions.php, (4) admin_board.php, (5) admin_attachments.php, or (6) admin_users.php in admin/.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0562">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_explorer:6.00.2900.2180"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:windows_explorer:6.00.2900.2180</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0562</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T11:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:00.817-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3190" xml:lang="en">3190</vuln:reference>
    </vuln:references>
    <vuln:summary>Windows Explorer (explorer.exe) 6.0.2900.2180 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted .avi file, which triggers the crash when the user right clicks on the file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0563">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:symantec:web_security:3.0.1.72"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:web_security:3.01.59"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:web_security:3.01.60"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:web_security:3.01.61"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:web_security:3.01.62"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:web_security:3.01.63"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:web_security:3.01.67"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:web_security:3.01.68"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:symantec:web_security:3.0.1.72</vuln:product>
      <vuln:product>cpe:/a:symantec:web_security:3.01.59</vuln:product>
      <vuln:product>cpe:/a:symantec:web_security:3.01.60</vuln:product>
      <vuln:product>cpe:/a:symantec:web_security:3.01.61</vuln:product>
      <vuln:product>cpe:/a:symantec:web_security:3.01.62</vuln:product>
      <vuln:product>cpe:/a:symantec:web_security:3.01.63</vuln:product>
      <vuln:product>cpe:/a:symantec:web_security:3.01.67</vuln:product>
      <vuln:product>cpe:/a:symantec:web_security:3.01.68</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0563</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T11:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:16.267-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://securityresponse.symantec.com/avcenter/security/Content/2007.01.24c.html" xml:lang="en">http://securityresponse.symantec.com/avcenter/security/Content/2007.01.24c.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017558" xml:lang="en">1017558</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22184" xml:lang="en">22184</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0330" xml:lang="en">ADV-2007-0330</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31750" xml:lang="en">symantec-html-xss(31750)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Symantec Web Security (SWS) before 3.0.1.85 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) error messages and (2) blocked page messages produced by SWS.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0564">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:symantec:web_security:3.0.1.72"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:web_security:3.01.59"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:web_security:3.01.60"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:web_security:3.01.61"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:web_security:3.01.62"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:web_security:3.01.63"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:web_security:3.01.67"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:web_security:3.01.68"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:symantec:web_security:3.0.1.72</vuln:product>
      <vuln:product>cpe:/a:symantec:web_security:3.01.59</vuln:product>
      <vuln:product>cpe:/a:symantec:web_security:3.01.60</vuln:product>
      <vuln:product>cpe:/a:symantec:web_security:3.01.61</vuln:product>
      <vuln:product>cpe:/a:symantec:web_security:3.01.62</vuln:product>
      <vuln:product>cpe:/a:symantec:web_security:3.01.63</vuln:product>
      <vuln:product>cpe:/a:symantec:web_security:3.01.67</vuln:product>
      <vuln:product>cpe:/a:symantec:web_security:3.01.68</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0564</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T11:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:50:17.703-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://securityresponse.symantec.com/avcenter/security/Content/2007.01.24c.html" xml:lang="en">http://securityresponse.symantec.com/avcenter/security/Content/2007.01.24c.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017558" xml:lang="en">1017558</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0330" xml:lang="en">ADV-2007-0330</vuln:reference>
    </vuln:references>
    <vuln:summary>The license registering interface in Symantec Web Security (SWS) before 3.0.1.85 allows attackers to cause a denial of service (CPU consumption) by submitting a large file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0565">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cgi-rescue:shopping_basket_professional:7.50"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cgi-rescue:shopping_basket_professional:7.50</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0565</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T11:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:41:05.170-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>JVN</vuln:source>
      <vuln:reference href="http://jvn.jp/jp/JVN%2382258242/index.html" xml:lang="en">JVN#82258242</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22245" xml:lang="en">22245</vuln:reference>
    </vuln:references>
    <vuln:summary>CGI-Rescue Shopping Basket Professional 7.50 and earlier allows remote attackers to inject arbitrary operating system commands via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0566">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:asp_news:asp_news:3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:asp_news:asp_news:3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0566</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T11:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:26.607-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458057/100/100/threaded" xml:lang="en">20070125 ASP NEWS &lt;= V3 (news_detail.asp) Remote SQL Injection Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22214" xml:lang="en">22214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0340" xml:lang="en">ADV-2007-0340</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31719" xml:lang="en">aspnews-newsdetail-sql-injection(31719)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3187" xml:lang="en">3187</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in news_detail.asp in ASP NEWS 3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0567">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:interactive-scripts.com:php_membership_manager:1.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:interactive-scripts.com:php_membership_manager:1.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0567</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:27.090-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458226/100/0/threaded" xml:lang="en">20070126 PHP Membership Manager Cross-Site Scripting Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22263" xml:lang="en">22263</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31916" xml:lang="en">phpmembership-admin-xss(31916)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in admin.php in Interactive-Scripts.Com PHP Membership Manager 1.5 allows remote attackers to inject arbitrary web script or HTML via the _p parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0568">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:myphpcommander:myphpcommander:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:myphpcommander:myphpcommander:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0568</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:00.940-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22257" xml:lang="en">22257</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0385" xml:lang="en">ADV-2007-0385</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31906" xml:lang="en">myphpcommander-package-file-include(31906)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3201" xml:lang="en">3201</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in system/lib/package.php in MyPHPCommander 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the gl_root parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0569">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:x-dev:xnews:1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:x-dev:xnews:1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0569</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:01.207-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22284" xml:lang="en">22284</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31855" xml:lang="en">xnews-xnews-sql-injection(31855)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3216" xml:lang="en">3216</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in xNews.php in xNews 1.3 allows remote attackers to execute arbitrary SQL commands via the id parameter in a shownews action.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0570">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:johannes_gijsbers:ad_fundum_integratable_news_script:0.02b"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:johannes_gijsbers:ad_fundum_integratable_news_script:0.02b</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0570</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:01.270-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22259" xml:lang="en">22259</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0384" xml:lang="en">ADV-2007-0384</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31850" xml:lang="en">ains-ainsmain-file-include(31850)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3202" xml:lang="en">3202</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in ains_main.php in Johannes Gijsbers (aka Taradino) Ad Fundum Integratable News Script (AINS) 0.02b allows remote attackers to execute arbitrary PHP code via a URL in the ains_path parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0571">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpmyreports:phpmyreports:3.0.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpmyreports:phpmyreports:3.0.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0571</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:01.333-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22290" xml:lang="en">22290</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0386" xml:lang="en">ADV-2007-0386</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31857" xml:lang="en">phpmyreports-libhead-file-include(31857)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3212" xml:lang="en">3212</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in include/lib/lib_head.php in phpMyReports 3.0.11 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cfgPathModule parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0572">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:drunken_golem:gaming_portal:0.5.1_alpha_2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:drunken_golem:gaming_portal:0.5.1_alpha_2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0572</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:01.393-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0390" xml:lang="en">ADV-2007-0390</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31873" xml:lang="en">drunkengolem-phpirc-file-include(31873)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3207" xml:lang="en">3207</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in include/irc/phpIRC.php in Drunken:Golem Gaming Portal 0.5.1 Alpha 2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0573">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nsgalphp:nsgalphp:0.41"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nsgalphp:nsgalphp:0.41</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0573</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:01.457-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-January/001257.html" xml:lang="en">VIM 20070130 Source VERIFY: nsGalPHP RFI</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22277" xml:lang="en">22277</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0392" xml:lang="en">ADV-2007-0392</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31861" xml:lang="en">nsgalphp-config-file-include(31861)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3205" xml:lang="en">3205</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in includes/config.inc.php in nsGalPHP 0.41 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the racineTBS parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0574">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:spoonlabs:vivvo_article_management_cms:3.40"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:spoonlabs:vivvo_article_management_cms:3.40</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0574</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-13T01:32:19.190-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22282" xml:lang="en">22282</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in rss/show_webfeed.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.40 allows remote attackers to execute arbitrary SQL commands via the wcHeadlines parameter, a different vector than CVE-2006-4715.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0575">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:stefan_holmberg:admentor"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:stefan_holmberg:admentor</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0575</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:27.403-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://forums.avenir-geopolitique.net/viewtopic.php?t=2606" xml:lang="en">http://forums.avenir-geopolitique.net/viewtopic.php?t=2606</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2207" xml:lang="en">2207</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458303/100/0/threaded" xml:lang="en">20070127 AdMentor (banners) admin SQL injection</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460632/100/100/threaded" xml:lang="en">20070220 AdMentor Script Remote SQL injection Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22281" xml:lang="en">22281</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31908" xml:lang="en">admentor-adminlogin-sql-injection(31908)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in the administrative login page (admin/login.asp) in ASPCode.net AdMentor allow remote attackers to execute arbitrary SQL commands via the (1) Userid and (2) Password fields.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0576">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:xt-stats:xt-stats:2.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:xt-stats:xt-stats:2.4.0.b3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xt-stats:xt-stats:2.3.0</vuln:product>
      <vuln:product>cpe:/a:xt-stats:xt-stats:2.4.0.b3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0576</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:01.520-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://seclists.org/bugtraq/2007/Jan/0643.html" xml:lang="en">20070127 Xt-Stats v.2.4.0.b3 - Remote File Include Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22276" xml:lang="en">22276</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0387" xml:lang="en">ADV-2007-0387</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.xt-scripts.com/" xml:lang="en">http://www.xt-scripts.com/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31871" xml:lang="en">xtstats-xtcounter-file-include(31871)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3209" xml:lang="en">3209</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in xt_counter.php in Xt-Stats 2.3.x up to 2.4.0.b3 allows remote attackers to execute arbitrary PHP code via a URL in the server_base_dir parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0577">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:acgvclick:acgvclick:0.2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:acgvclick:acgvclick:0.2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0577</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:01.567-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22278" xml:lang="en">22278</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0391" xml:lang="en">ADV-2007-0391</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31859" xml:lang="en">acgvclick-function-file-include(31859)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3206" xml:lang="en">3206</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in function.inc.php in ACGVclick 0.2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0578">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mpg123:mpg123:0.59m"/>
        <cpe-lang:fact-ref name="cpe:/a:mpg123:mpg123:0.59n"/>
        <cpe-lang:fact-ref name="cpe:/a:mpg123:mpg123:0.59o"/>
        <cpe-lang:fact-ref name="cpe:/a:mpg123:mpg123:0.59p"/>
        <cpe-lang:fact-ref name="cpe:/a:mpg123:mpg123:0.59q"/>
        <cpe-lang:fact-ref name="cpe:/a:mpg123:mpg123:0.59r"/>
        <cpe-lang:fact-ref name="cpe:/a:mpg123:mpg123:0.59s"/>
        <cpe-lang:fact-ref name="cpe:/a:mpg123:mpg123:0.62"/>
        <cpe-lang:fact-ref name="cpe:/a:mpg123:mpg123:0.63"/>
        <cpe-lang:fact-ref name="cpe:/a:mpg123:mpg123:pre0.59s"/>
        <cpe-lang:fact-ref name="cpe:/a:mpg123:mpg123:pre0.59s_r11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mpg123:mpg123:0.59m</vuln:product>
      <vuln:product>cpe:/a:mpg123:mpg123:0.59n</vuln:product>
      <vuln:product>cpe:/a:mpg123:mpg123:0.59o</vuln:product>
      <vuln:product>cpe:/a:mpg123:mpg123:0.59p</vuln:product>
      <vuln:product>cpe:/a:mpg123:mpg123:0.59q</vuln:product>
      <vuln:product>cpe:/a:mpg123:mpg123:0.59r</vuln:product>
      <vuln:product>cpe:/a:mpg123:mpg123:0.59s</vuln:product>
      <vuln:product>cpe:/a:mpg123:mpg123:0.62</vuln:product>
      <vuln:product>cpe:/a:mpg123:mpg123:0.63</vuln:product>
      <vuln:product>cpe:/a:mpg123:mpg123:pre0.59s</vuln:product>
      <vuln:product>cpe:/a:mpg123:mpg123:pre0.59s_r11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0578</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:50:19.533-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?group_id=135704&amp;release_id=478747" xml:lang="en">http://sourceforge.net/project/shownotes.php?group_id=135704&amp;release_id=478747</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:032" xml:lang="en">MDKSA-2007:032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mpg123.de/cgi-bin/news.cgi" xml:lang="en">http://www.mpg123.de/cgi-bin/news.cgi</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22274" xml:lang="en">22274</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0366" xml:lang="en">ADV-2007-0366</vuln:reference>
    </vuln:references>
    <vuln:summary>The http_open function in httpget.c in mpg123 before 0.64 allows remote attackers to cause a denial of service (infinite loop) by closing the HTTP connection early.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0579">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:horde:groupware:1.0_rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:horde:groupware:1.0_rc3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:horde:groupware:1.0_rc2</vuln:product>
      <vuln:product>cpe:/a:horde:groupware:1.0_rc3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0579</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:16.877-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.horde.org/archives/announce/2007/000308.html" xml:lang="en">[horde-announce] 20070114 Horde Groupware 1.0 (final)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.horde.org/archives/announce/2007/000309.html" xml:lang="en">[horde-announce] 20070114 Horde Groupware Webmail Edition 1.0 (final)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22273" xml:lang="en">22273</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0368" xml:lang="en">ADV-2007-0368</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31849" xml:lang="en">horde-calendar-file-include(31849)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the calendar component in Horde Groupware Webmail Edition before 1.0, and Groupware before 1.0, allows remote attackers to include certain files via unspecified vectors.  NOTE: some of these details are obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0580">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:javier_suarez_sanz:foro_domus:2.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:javier_suarez_sanz:foro_domus:2.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0580</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:01.627-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22285" xml:lang="en">22285</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0396" xml:lang="en">ADV-2007-0396</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31853" xml:lang="en">forodomus-menu-file-include(31853)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3215" xml:lang="en">3215</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in menu.php in Foro Domus 2.10 allows remote attackers to execute arbitrary PHP code via a URL in the sesion_idioma parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0581">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:eclipsebb:eclipsebb:0.5.0_lite"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:eclipsebb:eclipsebb:0.5.0_lite</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0581</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:27.887-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/466172/100/0/threaded" xml:lang="en">20070418 EclipseBB Remote File Inclusion</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22283" xml:lang="en">22283</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0397" xml:lang="en">ADV-2007-0397</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31852" xml:lang="en">eclipsebb-functions-file-include(31852)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3214" xml:lang="en">3214</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in functions.php in EclipseBB 0.5.0 Lite allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0582">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:chernobile:chernobile:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:chernobile:chernobile:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0582</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:01.737-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22280" xml:lang="en">22280</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31939" xml:lang="en">chernobile-default-sql-injection(31939)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3210" xml:lang="en">3210</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in default.asp in ChernobiLe 1.0 allows remote attackers to execute arbitrary SQL commands via the User (username) field.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0583">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:http_commander:http_commander:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:http_commander:http_commander:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0583</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:17.077-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22298" xml:lang="en">22298</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31877" xml:lang="en">httpcommander-multiple-xss(31877)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in HTTP Commander 6.0, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) LogoffMessage parameter to logofflast.aspx or the (2) txtUsername parameter to Default.aspx. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0584">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:g-neric:php_generic_library_and_framework"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:g-neric:php_generic_library_and_framework</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0584</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:28.513-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458556/100/0/threaded" xml:lang="en">20070129 PhP Generic library &amp; framework (include_path) Remote File Include Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22287" xml:lang="en">22287</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0394" xml:lang="en">ADV-2007-0394</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31895" xml:lang="en">phpgeneric-membremanager-file-include(31895)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3217" xml:lang="en">3217</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in membres/membreManager.php in PhP Generic Library &amp; Framework for comm (g-neric) allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0585">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:webfwlog:webfwlog:0.92"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:webfwlog:webfwlog:0.92</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0585</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-08-13T17:47:28.650-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://webfwlog.cvs.sourceforge.net/*checkout*/webfwlog/webfwlog/ChangeLog" xml:lang="en">http://webfwlog.cvs.sourceforge.net/*checkout*/webfwlog/webfwlog/ChangeLog</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22291" xml:lang="en">22291</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0399" xml:lang="en">ADV-2007-0399</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31881" xml:lang="en">webfwlog-debug-file-include(31881)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3222" xml:lang="en">3222</vuln:reference>
    </vuln:references>
    <vuln:summary>include/debug.php in Webfwlog 0.92 and earlier, when register_globals is enabled, allows remote attackers to obtain source code of files via the conffile parameter.  NOTE: some of these details are obtained from third party information.  It is likely that this issue can be exploited to conduct directory traversal attacks.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0588">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:quicktime:7.1.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0588</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-08-15T01:21:18.897-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305214" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" xml:lang="en">APPLE-SA-2007-03-13</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://security-protocols.com/sp-x43-advisory.php" xml:lang="en">http://security-protocols.com/sp-x43-advisory.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/396820" xml:lang="en">VU#396820</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22228" xml:lang="en">22228</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017760" xml:lang="en">1017760</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" xml:lang="en">TA07-072A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0930" xml:lang="en">ADV-2007-0930</vuln:reference>
    </vuln:references>
    <vuln:summary>The InternalUnpackBits function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PICT file that triggers memory corruption in the _GetSrcBits32ARGB function. NOTE: this issue might overlap CVE-2007-0462.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0589">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:forum_livre:forum_livre:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:forum_livre:forum_livre:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0589</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:01.910-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3197" xml:lang="en">3197</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in Forum Livre 1.0 allows remote attackers to execute arbitrary SQL commands via the user parameter to info_user.asp.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0590">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:forum_livre:forum_livre:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:forum_livre:forum_livre:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0590</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:01.957-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3197" xml:lang="en">3197</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in busca2.asp in Forum Livre 1.0 remote attackers to inject arbitrary web script or HTML via the palavra parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0591">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:vu_le_an:virtual_path:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vu_le_an:virtual_path:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0591</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:02.020-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22241" xml:lang="en">22241</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0352" xml:lang="en">ADV-2007-0352</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3198" xml:lang="en">3198</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in configure.php in Vu Le An Virtual Path (VirtualPath) 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0592">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:indexcor:ezdatabase:2.1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:indexcor:ezdatabase:2.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0592</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:30.073-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2196" xml:lang="en">2196</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458062/100/0/threaded" xml:lang="en">20070125 EzDatabase Multiple Cross-Site Scripting Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22235" xml:lang="en">22235</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31768" xml:lang="en">ezdatabase-adminpanel-xss(31768)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in EzDatabase 2.1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to admin/login.php and the Admin Panel Database.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0593">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:siteman:siteman:1.1.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:siteman:siteman:1.1.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0593</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:30.417-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2205" xml:lang="en">2205</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458092/100/0/threaded" xml:lang="en">20070125 [x0n3-h4ck] Siteman 1.1.11 Remote Md5 Hash Disclosure Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/31440" xml:lang="en">31440</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31780" xml:lang="en">siteman-members-information-disclosure(31780)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/45485" xml:lang="en">siteman-members-info-disclosure(45485)</vuln:reference>
    </vuln:references>
    <vuln:summary>Siteman 1.1.11 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing password hashes via a direct request for data/members.txt.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0594">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:siteman:siteman:2.0.x2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:siteman:siteman:2.0.x2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0594</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:30.980-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2206" xml:lang="en">2206</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458081/100/0/threaded" xml:lang="en">20070125 [x0n3-h4ck] Siteman 2.0.x2 Remote Md5 Hash Disclosure Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>Siteman 2.0.x2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing password hashes via a direct request for db/siteman/users.MYD.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0595">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:designmind:high5_review_script"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:designmind:high5_review_script</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0595</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:31.183-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458122/100/0/threaded" xml:lang="en">20070125 high5 Review script Security Risk</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0363" xml:lang="en">ADV-2007-0363</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31797" xml:lang="en">high5review-search-xss(31797)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in search in High 5 Review Site allows remote attackers to inject arbitrary web script or HTML via the q parameter (aka the search box).</vuln:summary>
  </entry>
  <entry id="CVE-2007-0596">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:aztek_forum:aztek_forum:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:aztek_forum:aztek_forum:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0596</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:31.543-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://acid-root.new.fr/poc/21070125.txt" xml:lang="en">http://acid-root.new.fr/poc/21070125.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458076/100/0/threaded" xml:lang="en">20070125 Aztek Forum 4.1 Multiple Vulnerabilities Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458123/100/0/threaded" xml:lang="en">20070125 Re: Aztek Forum 4.1 Multiple Vulnerabilities Exploit</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in index/main.php in Aztek Forum 4.00 allows remote authenticated administrators to execute arbitrary PHP code via a URL in the PF[top_url] parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0597">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:aztek_forum:aztek_forum:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:aztek_forum:aztek_forum:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0597</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:31.840-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://acid-root.new.fr/poc/21070125.txt" xml:lang="en">http://acid-root.new.fr/poc/21070125.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458076/100/0/threaded" xml:lang="en">20070125 Aztek Forum 4.1 Multiple Vulnerabilities Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458123/100/0/threaded" xml:lang="en">20070125 Re: Aztek Forum 4.1 Multiple Vulnerabilities Exploit</vuln:reference>
    </vuln:references>
    <vuln:summary>Aztek Forum 4.00 allows remote attackers to obtain sensitive information via a direct request to forum.php with the fid=XD query string, which reveals the path in an error message.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0598">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:aztek_forum:aztek_forum:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:aztek_forum:aztek_forum:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0598</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:32.137-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://acid-root.new.fr/poc/21070125.txt" xml:lang="en">http://acid-root.new.fr/poc/21070125.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458076/100/0/threaded" xml:lang="en">20070125 Aztek Forum 4.1 Multiple Vulnerabilities Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458123/100/0/threaded" xml:lang="en">20070125 Re: Aztek Forum 4.1 Multiple Vulnerabilities Exploit</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in forum/load.php in Aztek Forum 4.00 allows remote attackers to execute arbitrary SQL commands via the fid cookie to forum.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0599">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:aztek_forum:aztek_forum:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:aztek_forum:aztek_forum:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0599</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:32.433-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://acid-root.new.fr/poc/21070125.txt" xml:lang="en">http://acid-root.new.fr/poc/21070125.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458076/100/0/threaded" xml:lang="en">20070125 Aztek Forum 4.1 Multiple Vulnerabilities Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458123/100/0/threaded" xml:lang="en">20070125 Re: Aztek Forum 4.1 Multiple Vulnerabilities Exploit</vuln:reference>
    </vuln:references>
    <vuln:summary>Variable overwrite vulnerability in common/config.php in Aztek Forum 4.00 allows remote attackers to overwrite arbitrary program variables and conduct other unauthorized activities, such as copying arbitrary files using index/common_actions.php, via vectors associated with extract operations on the (1) POST, (2) GET, (3) COOKIE, and (4) SERVER superglobal arrays.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0600">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:makit:newsposter_script:0"/>
        <cpe-lang:fact-ref name="cpe:/a:martyn_kilbryde:newsposter_script:3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:makit:newsposter_script:0</vuln:product>
      <vuln:product>cpe:/a:martyn_kilbryde:newsposter_script:3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0600</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:32.747-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2208" xml:lang="en">2208</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458063/100/0/threaded" xml:lang="en">20070125 makit news/blog poster &lt;=v3(news_page.asp) Remote SQL Injection Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22230" xml:lang="en">22230</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0354" xml:lang="en">ADV-2007-0354</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31747" xml:lang="en">newsposter-newspage-sql-injection(31747)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3194" xml:lang="en">3194</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in news_page.asp in Martyn Kilbryde Newsposter Script (aka makit news/blog poster) 3 and earlier allows remote attackers to execute arbitrary SQL commands via the uid parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0601">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:aztek_forum:aztek_forum:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:aztek_forum:aztek_forum:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0601</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:33.387-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://acid-root.new.fr/poc/21070125.txt" xml:lang="en">http://acid-root.new.fr/poc/21070125.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458076/100/0/threaded" xml:lang="en">20070125 Aztek Forum 4.1 Multiple Vulnerabilities Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458123/100/0/threaded" xml:lang="en">20070125 Re: Aztek Forum 4.1 Multiple Vulnerabilities Exploit</vuln:reference>
    </vuln:references>
    <vuln:summary>common/safety.php in Aztek Forum 4.00 allows remote attackers to enter certain data containing %22 sequences (URL encoded double quotes) and other potentially dangerous manipulations by sending a cookie, which bypasses the blacklist matching against the GET and PUT superglobal arrays.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0602">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:viruswall:3.81"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:trend_micro:viruswall:3.81</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0602</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:33.700-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034124&amp;id=EN-1034124" xml:lang="en">http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034124&amp;id=EN-1034124</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2204" xml:lang="en">2204</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017562" xml:lang="en">1017562</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.devtarget.org/tmvwall381v3_exp.c" xml:lang="en">http://www.devtarget.org/tmvwall381v3_exp.c</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.devtarget.org/trendmicro-advisory-01-2007.txt" xml:lang="en">http://www.devtarget.org/trendmicro-advisory-01-2007.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458111/100/0/threaded" xml:lang="en">20070125 Buffer overflow in VSAPI library of Trend Micro VirusWall 3.81 for Linux</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0367" xml:lang="en">ADV-2007-0367</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in libvsapi.so in the VSAPI library in Trend Micro VirusWall 3.81 for Linux, as used by IScan.BASE/vscan, allows local users to gain privileges via a long command line argument, a different vulnerability than CVE-2005-0533.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0603">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:pgp:corporate_desktop:9.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:pgp:corporate_desktop:9.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0603</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:34.200-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2007-q1/0025.html" xml:lang="en">20070125 Medium Risk Vulnerability in PGP Desktop</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2203" xml:lang="en">2203</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017563" xml:lang="en">1017563</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/102465" xml:lang="en">VU#102465</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.ngssoftware.com/advisories/medium-risk-vulnerability-in-pgp-desktop/" xml:lang="en">http://www.ngssoftware.com/advisories/medium-risk-vulnerability-in-pgp-desktop/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458137/100/0/threaded" xml:lang="en">20070125 Medium Risk Vulnerability in PGP Desktop</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22247" xml:lang="en">22247</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0356" xml:lang="en">ADV-2007-0356</vuln:reference>
    </vuln:references>
    <vuln:summary>PGP Desktop before 9.5.1 does not validate data objects received over the (1) \pipe\pgpserv named pipe for PGPServ.exe or the (2) \pipe\pgpsdkserv named pipe for PGPsdkServ.exe, which allows remote authenticated users to gain privileges by sending a data object representing an absolute pointer, which causes code execution at the corresponding address.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0604">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:six_apart_ltd:movable_type:3.33"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:six_apart_ltd:movable_type:3.33</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0604</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:41:12.420-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.sixapart.com/movabletype/beta/distros/MT-3.34-beta-Release-Notes.html" xml:lang="en">http://www.sixapart.com/movabletype/beta/distros/MT-3.34-beta-Release-Notes.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Movable Type (MT) before 3.34 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the MTCommentPreviewIsStatic tag, which can open the "comment entry screen," a different vulnerability than CVE-2007-0231.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0605">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:advanced_guestbook:advanced_guestbook:2.4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:advanced_guestbook:advanced_guestbook:2.4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0605</vuln:cve-id>
    <vuln:published-datetime>2007-05-09T13:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:34.870-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2663" xml:lang="en">2663</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.netvigilance.com/advisory0012" xml:lang="en">http://www.netvigilance.com/advisory0012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/467937/100/0/threaded" xml:lang="en">20070507 Advanced Guestbook version 2.4.2 Multiple XSS Attack Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23873" xml:lang="en">23873</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1726" xml:lang="en">ADV-2007-1726</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/34156" xml:lang="en">advanced-picture-index-xss(34156)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in picture.php in Advanced Guestbook 2.4.2 allows remote attackers to inject arbitrary web script or HTML via the picture parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0606">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:w-agora:w-agora:4.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:w-agora:w-agora:4.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0606</vuln:cve-id>
    <vuln:published-datetime>2007-03-21T15:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:35.467-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2461" xml:lang="en">2461</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.netvigilance.com/advisory0014" xml:lang="en">http://www.netvigilance.com/advisory0014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/463213/100/0/threaded" xml:lang="en">20070319 w-agora version 4.2.1 Multiple Path Disclosure Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33076" xml:lang="en">wagora-deleteforumindex-path-disclosure(33076)</vuln:reference>
    </vuln:references>
    <vuln:summary>w-agora 4.2.1 allows remote attackers to obtain sensitive information by via the (1) bn[] array parameter to index.php, which expects a string, and (2) certain parameters to delete_forum.php, which displays the path name in the resulting error message.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0607">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:w-agora:w-agora:4.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:w-agora:w-agora:4.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0607</vuln:cve-id>
    <vuln:published-datetime>2007-03-20T16:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:35.917-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-March/053054.html" xml:lang="en">20070319 w-agora version 4.2.1 Information Disclosure Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2465" xml:lang="en">2465</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.netvigilance.com/advisory0015" xml:lang="en">http://www.netvigilance.com/advisory0015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/463215/100/0/threaded" xml:lang="en">20070319 w-agora version 4.2.1 Information Disclosure Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33073" xml:lang="en">wagora-globals-information-disclosure(33073)</vuln:reference>
    </vuln:references>
    <vuln:summary>W-Agora (Web-Agora) 4.2.1, when register_globals is enabled, stores globals.inc under the web document root with insufficient access control, which allows remote attackers to obtain application path information via a direct request.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0608">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:advanced_guestbook:advanced_guestbook:2.4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:advanced_guestbook:advanced_guestbook:2.4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0608</vuln:cve-id>
    <vuln:published-datetime>2007-05-09T13:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:36.387-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2661" xml:lang="en">2661</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.netvigilance.com/advisory0011" xml:lang="en">http://www.netvigilance.com/advisory0011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/467940/100/0/threaded" xml:lang="en">20070507 Advanced Guestbook version 2.4.2 Multiple Error Information Leak Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1726" xml:lang="en">ADV-2007-1726</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/34161" xml:lang="en">advanced-multiple-script-info-disclosure(34161)</vuln:reference>
    </vuln:references>
    <vuln:summary>Advanced Guestbook 2.4.2 allows remote attackers to obtain sensitive information via an invalid (1) GB_TBL parameter to (a) lang/codes-english.php or (b) image.php, which reveal the database name; (2) an invalid GB_DB parameter to index.php, coupled with a ../index lang cookie, which reveals the installation path; or (3) a direct request to index.php with no parameters or cookies, which reveals the installation path.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0609">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:advanced_guestbook:advanced_guestbook:2.4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:advanced_guestbook:advanced_guestbook:2.4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0609</vuln:cve-id>
    <vuln:published-datetime>2007-05-09T13:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:37.107-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2662" xml:lang="en">2662</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.netvigilance.com/advisory0012" xml:lang="en">http://www.netvigilance.com/advisory0012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.netvigilance.com/advisory0013" xml:lang="en">http://www.netvigilance.com/advisory0013</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/467937/100/0/threaded" xml:lang="en">20070507 Advanced Guestbook version 2.4.2 Multiple XSS Attack Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/467941/100/0/threaded" xml:lang="en">20070507 Advanced Guestbook version 2.4.2 Directory Traversal Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23876" xml:lang="en">23876</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1726" xml:lang="en">ADV-2007-1726</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/34152" xml:lang="en">advanced-index-directory-traversal(34152)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in Advanced Guestbook 2.4.2 allows remote attackers to bypass .htaccess settings, and execute arbitrary PHP local files or read arbitrary local templates, via a .. (dot dot) in a lang cookie, followed by a filename without its .php extension, as demonstrated via a request to index.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0610">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cmsmadesimple:cms_made_simple:2.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cmsmadesimple:cms_made_simple:2.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0610</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:17.703-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22250" xml:lang="en">22250</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31841" xml:lang="en">cmsimple-sender-xss(31841)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the mailform feature in CMSimple 2.7 fix1 allows remote attackers to inject arbitrary web script or HTML via the sender parameter.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0611">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:free_lan_intra_internet_portal:free_lan_intra_internet_portal:1.0_rc1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:free_lan_intra_internet_portal:free_lan_intra_internet_portal:1.0_rc1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0611</vuln:cve-id>
    <vuln:published-datetime>2007-01-30T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:50:23.500-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=480714&amp;group_id=98260" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=480714&amp;group_id=98260</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0360" xml:lang="en">ADV-2007-0360</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Free LAN In(tra|ter)net Portal (FLIP) before 1.0-RC2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors in (1) inc.page.php and (2) inc.text.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0612">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp4"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0_ta3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7.0::vista"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7.0:beta2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp4</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.0_ta3</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:5.5</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:7.0::vista</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:7.0:beta1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:7.0:beta2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0612</vuln:cve-id>
    <vuln:published-datetime>2007-01-31T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:37.840-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0547.html" xml:lang="en">20070128 Internet Explorer 7 ActiveX bgColor property NULL pointer dereference (DoS)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/052057.html" xml:lang="en">20070129 Internet Explorer 7 ActiveX bgColor property NULL pointer dereference (DoS)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2199" xml:lang="en">2199</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.determina.com/security.research/vulnerabilities/activex-bgcolor.html" xml:lang="en">http://www.determina.com/security.research/vulnerabilities/activex-bgcolor.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458443/100/0/threaded" xml:lang="en">20070129 Internet Explorer 7 ActiveX bgColor property NULL pointer dereference (DoS)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22288" xml:lang="en">22288</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31867" xml:lang="en">ie-activex-bgcolor-dos(31867)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple ActiveX controls in Microsoft Windows 2000, XP, 2003, and Vista allows remote attackers to cause a denial of service (Internet Explorer crash) by accessing the bgColor, fgColor, linkColor, alinkColor, vlinkColor, or defaultCharset properties in the (1) giffile, (2) htmlfile, (3) jpegfile, (4) mhtmlfile, (5) ODCfile, (6) pjpegfile, (7) pngfile, (8) xbmfile, (9) xmlfile, (10) xslfile, or (11) wdfile objects in (a) mshtml.dll; or the (12) TriEditDocument.TriEditDocument or (13) TriEditDocument.TriEditDocument.1 objects in (b) triedit.dll, which cause a NULL pointer dereference.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0613">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:ichat:3.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:instant_message_framework:428"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:mdnsresponder"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:ichat:3.1.6</vuln:product>
      <vuln:product>cpe:/a:apple:instant_message_framework:428</vuln:product>
      <vuln:product>cpe:/a:apple:mdnsresponder</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0613</vuln:cve-id>
    <vuln:published-datetime>2007-01-31T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:18:21.727-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-31T17:24:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-29-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-29-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22304" xml:lang="en">22304</vuln:reference>
    </vuln:references>
    <vuln:summary>The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 does not check for duplicate entries when adding newly discovered available contacts, which allows remote attackers to cause a denial of service (disrupted communication) via a flood of duplicate _presence._tcp mDNS queries.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0614">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:ichat:3.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:instant_message_framework:428"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:ichat:3.1.6</vuln:product>
      <vuln:product>cpe:/a:apple:instant_message_framework:428</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0614</vuln:cve-id>
    <vuln:published-datetime>2007-01-31T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:18:21.880-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-01-31T17:34:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305102" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305102</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Feb/msg00000.html" xml:lang="en">APPLE-SA-2007-02-15</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-29-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-29-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22304" xml:lang="en">22304</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017661" xml:lang="en">1017661</vuln:reference>
    </vuln:references>
    <vuln:summary>The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 allows remote attackers to cause a denial of service (persistent application crash) via a crafted phsh hash attribute in a TXT key.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0615">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:hitachi:hibun_advanced_edition_server:r-1v13-06w001f1"/>
        <cpe-lang:fact-ref name="cpe:/a:hitachi:jpi_hibun_advanced_edition_server:r_1543h_11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hitachi:hibun_advanced_edition_server:r-1v13-06w001f1</vuln:product>
      <vuln:product>cpe:/a:hitachi:jpi_hibun_advanced_edition_server:r_1543h_11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0615</vuln:cve-id>
    <vuln:published-datetime>2007-01-31T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:17.797-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.hitachi-support.com/security_e/vuls_e/HS06-019_e/01-e.html" xml:lang="en">http://www.hitachi-support.com/security_e/vuls_e/HS06-019_e/01-e.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22237" xml:lang="en">22237</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0324" xml:lang="en">ADV-2007-0324</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31733" xml:lang="en">hitachi-jp1-hibun-request-dos(31733)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Hitachi JP1/HIBUN Advanced Edition Management Server and Log Server before 20070124 allows remote attackers to cause a denial of service (application stop) via unexpected data.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0616">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:zenphoto:zenphoto:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:zenphoto:zenphoto:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:zenphoto:zenphoto:1.0.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:zenphoto:zenphoto:1.0.4</vuln:product>
      <vuln:product>cpe:/a:zenphoto:zenphoto:1.0.5</vuln:product>
      <vuln:product>cpe:/a:zenphoto:zenphoto:1.0.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0616</vuln:cve-id>
    <vuln:published-datetime>2007-01-31T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:17.843-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22368" xml:lang="en">22368</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0470" xml:lang="en">ADV-2007-0470</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zenphoto.org/support/topic.php?id=1146&amp;replies=3" xml:lang="en">http://www.zenphoto.org/support/topic.php?id=1146&amp;replies=3</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.zenphoto.org/support/topic.php?id=1148" xml:lang="en">http://www.zenphoto.org/support/topic.php?id=1148</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32102" xml:lang="en">zenphoto-template-directory-traversal(32102)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in zen/template-functions.php in zenphoto 1.0.4 up to 1.0.6 allows remote attackers to list arbitrary directories via ".." sequences in the album parameter to index.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0617">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:earthlink:total_access"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:earthlink:total_access</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0617</vuln:cve-id>
    <vuln:published-datetime>2007-01-31T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:17.937-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/052021.html" xml:lang="en">20070125 Earthlink TotalAccess ActiveX Unsafe Methods Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2210" xml:lang="en">2210</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22238" xml:lang="en">22238</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31827" xml:lang="en">earthlink-spamblocker-security-bypass(31827)</vuln:reference>
    </vuln:references>
    <vuln:summary>The SpamBlocker.dll ActiveX control in Earthlink TotalAccess is marked "safe for scripting," which allows remote attackers to add arbitrary e-mail addresses and domains to the spam blocker whitelist via the (1) AddSenderToWhitelist and (2) AddDomainToWhitelist functions.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0618">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:5.3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0618</vuln:cve-id>
    <vuln:published-datetime>2007-01-31T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:18.017-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="ftp://aix.software.ibm.com/aix/efixes/security/README" xml:lang="en">ftp://aix.software.ibm.com/aix/efixes/security/README</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22262" xml:lang="en">22262</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0382" xml:lang="en">ADV-2007-0382</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY93084&amp;apar=only" xml:lang="en">IY93084</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31875" xml:lang="en">aix-mailservices-rlogin-security-bypass(31875)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in (1) pop3d, (2) pop3ds, (3) imapd, and (4) imapds in IBM AIX 5.3.0 has unspecified impact and attack vectors, involving an "authentication vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0619">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:chmlib:chmlib:0.38"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:chmlib:chmlib:0.38</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0619</vuln:cve-id>
    <vuln:published-datetime>2007-01-31T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:50:24.687-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=468" xml:lang="en">20070126 Multiple Vendor libchm Page Block Length Memory Corruption Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://morte.jedrea.com/~jedwin/projects/chmlib/" xml:lang="en">http://morte.jedrea.com/~jedwin/projects/chmlib/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200702-12.xml" xml:lang="en">GLSA-200702-12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017565" xml:lang="en">1017565</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_3_sr.html" xml:lang="en">SUSE-SR:2007:003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22258" xml:lang="en">22258</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0361" xml:lang="en">ADV-2007-0361</vuln:reference>
    </vuln:references>
    <vuln:summary>chmlib before 0.39 allows user-assisted remote attackers to execute arbitrary code via a crafted page block length in a CHM file, which triggers memory corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0620">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:vlad_leont:fd_script:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:vlad_leont:fd_script:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:vlad_leont:fd_script:1.3.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vlad_leont:fd_script:1.3</vuln:product>
      <vuln:product>cpe:/a:vlad_leont:fd_script:1.3.1</vuln:product>
      <vuln:product>cpe:/a:vlad_leont:fd_script:1.3.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0620</vuln:cve-id>
    <vuln:published-datetime>2007-01-31T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:38.467-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2197" xml:lang="en">2197</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458231/100/0/threaded" xml:lang="en">20070126 FdScript &lt;= v1.3.2 Remote File Disclosure Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22265" xml:lang="en">22265</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0383" xml:lang="en">ADV-2007-0383</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31915" xml:lang="en">fdscript-download-file-disclosure(31915)</vuln:reference>
    </vuln:references>
    <vuln:summary>download.php in FD Script 1.3.2 and earlier allows remote attackers to read source of files under the web document root with certain extensions, including .php, via a relative pathname in the fname parameter, as demonstrated by downloading config.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0621">
    <vuln:cve-id>CVE-2007-0621</vuln:cve-id>
    <vuln:published-datetime>2007-01-31T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:49:43.820-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-6456.  Reason: This candidate is a duplicate of CVE-2006-6456.  It was assigned for a targeted zero-day attack, but further analysis revealed it was for an older issue.  Notes: All CVE users should reference CVE-2006-6456 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0622">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mybb:mybb:1.2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mybb:mybb:1.2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0622</vuln:cve-id>
    <vuln:published-datetime>2007-01-31T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:41:15.217-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Cross-site request forgery (CSRF) vulnerability in MyBB (aka MyBulletinBoard) 1.2.2 allows remote attackers to send messages to arbitrary users.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0623">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:maxdev:mdpro:1.0.76"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:maxdev:mdpro:1.0.76</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0623</vuln:cve-id>
    <vuln:published-datetime>2007-01-31T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:38.950-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2198" xml:lang="en">2198</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458438/100/0/threaded" xml:lang="en">20070129 MDPro 1.0.76 - Multiple Remote Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22293" xml:lang="en">22293</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0412" xml:lang="en">ADV-2007-0412</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31897" xml:lang="en">mdpro-startrow-sql-injection(31897)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in index.php in MAXdev MDPro 1.0.76 allows remote attackers to execute arbitrary SQL commands via the startrow parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0624">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:maxdev:mdpro:1.0.76"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:maxdev:mdpro:1.0.76</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0624</vuln:cve-id>
    <vuln:published-datetime>2007-01-31T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:39.450-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2198" xml:lang="en">2198</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458438/100/0/threaded" xml:lang="en">20070129 MDPro 1.0.76 - Multiple Remote Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31898" xml:lang="en">mdpro-user-path-disclosure(31898)</vuln:reference>
    </vuln:references>
    <vuln:summary>user.php in MAXdev MDPro 1.0.76 allows remote attackers to obtain the full path via a ' (quote) character, and possibly other invalid values, in the uname parameter in a userinfo operation.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0625">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nomachine:nx_server:2.1.0_17"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nomachine:nx_server:2.1.0_17</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0625</vuln:cve-id>
    <vuln:published-datetime>2007-01-31T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:18.237-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.nomachine.com/news_read.php?idnews=190" xml:lang="en">http://www.nomachine.com/news_read.php?idnews=190</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.nomachine.com/tr/view.php?id=TR01E01622" xml:lang="en">http://www.nomachine.com/tr/view.php?id=TR01E01622</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22308" xml:lang="en">22308</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0413" xml:lang="en">ADV-2007-0413</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31941" xml:lang="en">nxserver-nxconfigure-dos(31941)</vuln:reference>
    </vuln:references>
    <vuln:summary>nxconfigure.sh in NoMachine NX Server before 2.1.0-18 does not validate the invoking user, which allows local users to modify server configuration keys in /usr/NX/etc/server.cfg, resulting in an unspecified denial of service.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0626">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.7"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.8"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.9"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.10"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.6.11"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.0:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.0:beta5"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.0:beta6"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.0:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.4"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.5"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:5.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:5.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:5.0:dev"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:5.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:5.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:vbdrupal:vbdrupal:-"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:drupal:drupal:4.1.0</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.2.0</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.3.0</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.3.1</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.3.2</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.4.0</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.4.1</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.4.2</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.4.3</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.5.0</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.5.1</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.5.2</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.5.3</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.5.4</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.5.5</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.5.6</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.5.7</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.5.8</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.0</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.1</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.2</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.3</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.4</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.5</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.6</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.7</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.8</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.9</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.10</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.6.11</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.0</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.0:beta3</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.0:beta4</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.0:beta5</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.0:beta6</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.0:rc1</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.0:rc2</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.0:rc3</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.0:rc4</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.1</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.2</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.3</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.4</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.5</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:5.0</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:5.0:beta1</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:5.0:beta2</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:5.0:dev</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:5.0:rc1</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:5.0:rc2</vuln:product>
      <vuln:product>cpe:/a:vbdrupal:vbdrupal:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0626</vuln:cve-id>
    <vuln:published-datetime>2007-01-31T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T13:45:09.170-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2018-10-18T08:01:01.623-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/2007-01/0670.html" xml:lang="en">20070129 [DRUPAL-SA-2007-005] Drupal 4.7.6 / 5.1 fixes arbitrary code execution issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://drupal.org/node/113935" xml:lang="en">http://drupal.org/node/113935</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22306" xml:lang="en">22306</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vbdrupal.org/forum/showthread.php?t=786" xml:lang="en">http://www.vbdrupal.org/forum/showthread.php?t=786</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0406" xml:lang="en">ADV-2007-0406</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0415" xml:lang="en">ADV-2007-0415</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31940" xml:lang="en">drupal-commentformaddpreview-code-execution(31940)</vuln:reference>
    </vuln:references>
    <vuln:summary>The comment_form_add_preview function in comment.module in Drupal before 4.7.6, and 5.x before 5.1, and vbDrupal, allows remote attackers with "post comments" privileges and access to multiple input filters to execute arbitrary code by previewing comments, which are not processed by "normal form validation routines."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0627">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:michael_still:gtalkbot:1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:michael_still:gtalkbot:1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0627</vuln:cve-id>
    <vuln:published-datetime>2007-01-31T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:18.360-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://freshmeat.net/projects/gtalkbot/?branch_id=67830&amp;release_id=245004" xml:lang="en">http://freshmeat.net/projects/gtalkbot/?branch_id=67830&amp;release_id=245004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22322" xml:lang="en">22322</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.stillhq.com/gtalkbot/" xml:lang="en">http://www.stillhq.com/gtalkbot/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.stillhq.com/gtalkbot/000003.html" xml:lang="en">http://www.stillhq.com/gtalkbot/000003.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0408" xml:lang="en">ADV-2007-0408</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31923" xml:lang="en">gtalkbot-ps-information-disclosure(31923)</vuln:reference>
    </vuln:references>
    <vuln:summary>Michael Still gtalkbot before 1.2 places username and password arguments on the command line, which allows local users to obtain sensitive information by listing the process.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0628">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sun:java_system_access_manager:6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:java_system_access_manager:6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:java_system_access_manager:6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:java_system_access_manager:7.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:java_system_access_manager:6.1</vuln:product>
      <vuln:product>cpe:/a:sun:java_system_access_manager:6.2</vuln:product>
      <vuln:product>cpe:/a:sun:java_system_access_manager:6.3</vuln:product>
      <vuln:product>cpe:/a:sun:java_system_access_manager:7.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0628</vuln:cve-id>
    <vuln:published-datetime>2007-01-31T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:18.423-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017570" xml:lang="en">1017570</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102621-1" xml:lang="en">102621</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22302" xml:lang="en">22302</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0411" xml:lang="en">ADV-2007-0411</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31936" xml:lang="en">java-access-server-unspecified-xss(31936)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Access Manager 6.1, 6.2, 6 2005Q1 (6.3), and 7 2005Q4 (7.0) before 20070129 allow remote attackers to inject arbitrary web script or HTML via the (1) goto or (2) gx-charset parameter. NOTE: some of these details are obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0629">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:plain_black:webgui:7.3.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:plain_black:webgui:7.3.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0629</vuln:cve-id>
    <vuln:published-datetime>2007-01-31T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:18.487-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?group_id=51417&amp;release_id=481584" xml:lang="en">http://sourceforge.net/project/shownotes.php?group_id=51417&amp;release_id=481584</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.plainblack.com/getwebgui/advisories/security-defect-discovered-in-7.x-versions" xml:lang="en">http://www.plainblack.com/getwebgui/advisories/security-defect-discovered-in-7.x-versions</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22294" xml:lang="en">22294</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31905" xml:lang="en">webgui-wwwpurgelist-security-bypass(31905)</vuln:reference>
    </vuln:references>
    <vuln:summary>The www_purgeList method in Plain Black WebGUI before 7.3.8 does not properly check user permissions, which allows attackers to delete unauthorized assets.  NOTE: some of these details are obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0630">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:x-dev:xnews:1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:x-dev:xnews:1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0630</vuln:cve-id>
    <vuln:published-datetime>2007-01-31T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:50:25.813-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0395" xml:lang="en">ADV-2007-0395</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in the generate_csv function in classes/class.news.php in X-dev xNews 1.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) from, and (3) q parameters, different vectors than CVE-2007-0569.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0631">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:eclectic_designs:cascadianfaq:4.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:eclectic_designs:cascadianfaq:4.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0631</vuln:cve-id>
    <vuln:published-datetime>2007-01-31T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:02.143-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22314" xml:lang="en">22314</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0424" xml:lang="en">ADV-2007-0424</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31968" xml:lang="en">cascadianfaq-index-sql-injection(31968)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3227" xml:lang="en">3227</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in index.php in Eclectic Designs CascadianFAQ 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0632">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:asp_edge:asp_edge:1.3a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:asp_edge:asp_edge:1.3a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0632</vuln:cve-id>
    <vuln:published-datetime>2007-01-31T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:50:26.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0341" xml:lang="en">ADV-2007-0341</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in artreplydelete.asp in ASP EDGE 1.3a and earlier allows remote attackers to execute arbitrary SQL commands via a username cookie, a different vector than CVE-2007-0560.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0633">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:t-systems_solutions_for_research_gmbh:mynews:4.2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:t-systems_solutions_for_research_gmbh:mynews:4.2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0633</vuln:cve-id>
    <vuln:published-datetime>2007-01-31T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:02.190-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22313" xml:lang="en">22313</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0423" xml:lang="en">ADV-2007-0423</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31971" xml:lang="en">mynews-themefunc-file-include(31971)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3228" xml:lang="en">3228</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in include/themes/themefunc.php in MyNews 4.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the myNewsConf[path][sys][index] parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0634">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:10.0::sparc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:10.0::sparc</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0634</vuln:cve-id>
    <vuln:published-datetime>2007-01-31T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:38.267-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1249" name="oval:org.mitre.oval:def:1249"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017574" xml:lang="en">1017574</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102697-1" xml:lang="en">102697</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/967236" xml:lang="en">VU#967236</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22323" xml:lang="en">22323</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0420" xml:lang="en">ADV-2007-0420</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32010" xml:lang="en">solaris-icmp-dos(32010)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Sun Solaris 10 before 20070130 allows remote attackers to cause a denial of service (system crash) via certain ICMP packets.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0635">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:encapscms:encapscms:0.3.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:encapscms:encapscms:0.3.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0635</vuln:cve-id>
    <vuln:published-datetime>2007-01-31T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:39.747-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2200" xml:lang="en">2200</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458582/100/0/threaded" xml:lang="en">20070130 EncapsCMS 0.3.6 (common_foot.php) Remote File Include</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22319" xml:lang="en">22319</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0430" xml:lang="en">ADV-2007-0430</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31978" xml:lang="en">encapsms-config-file-include(31978)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple PHP remote file inclusion vulnerabilities in EncapsCMS 0.3.6 allow remote attackers to execute arbitrary PHP code via a URL in the (1) config[path] parameter to (a) common_foot.php or (b) blogs.php, or (2) the config[theme] parameter to (c) admin/gallery_head.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0636">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:inotify:incron:0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:inotify:incron:0.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:inotify:incron:0.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:inotify:incron:0.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:inotify:incron:0.3.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:inotify:incron:0.3</vuln:product>
      <vuln:product>cpe:/a:inotify:incron:0.3.1</vuln:product>
      <vuln:product>cpe:/a:inotify:incron:0.3.2</vuln:product>
      <vuln:product>cpe:/a:inotify:incron:0.3.3</vuln:product>
      <vuln:product>cpe:/a:inotify:incron:0.3.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0636</vuln:cve-id>
    <vuln:published-datetime>2007-01-31T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:50:26.470-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://inotify.aiken.cz/?section=incron&amp;page=changelog" xml:lang="en">http://inotify.aiken.cz/?section=incron&amp;page=changelog</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22305" xml:lang="en">22305</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0405" xml:lang="en">ADV-2007-0405</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in inotify before 0.3.5 has unknown impact and attack vectors, related to "access rights to watched files."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0637">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:galeria_zdjec:galeria_zdjec:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:galeria_zdjec:galeria_zdjec:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0637</vuln:cve-id>
    <vuln:published-datetime>2007-01-31T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:02.427-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22324" xml:lang="en">22324</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0425" xml:lang="en">ADV-2007-0425</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31967" xml:lang="en">galeria-zdnumer-file-include(31967)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3225" xml:lang="en">3225</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in zd_numer.php in Galeria Zdjec 3.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the galeria parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by zd_numer.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0638">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:vlad_alexa_mancini:phpfootball:1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vlad_alexa_mancini:phpfootball:1.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0638</vuln:cve-id>
    <vuln:published-datetime>2007-01-31T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:02.690-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22312" xml:lang="en">22312</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0429" xml:lang="en">ADV-2007-0429</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31976" xml:lang="en">phpfootball-show-information-disclosure(31976)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3226" xml:lang="en">3226</vuln:reference>
    </vuln:references>
    <vuln:summary>show.php in Vlad Alexa Mancini PHPFootball 1.6 allows remote attackers to obtain sensitive information (database contents) via a % (percent) character in the dbfieldv parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0639">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:guppy:guppy:4.5.16"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:guppy:guppy:4.5.16</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0639</vuln:cve-id>
    <vuln:published-datetime>2007-01-31T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:02.770-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://retrogod.altervista.org/guppy_4516_cmd.html" xml:lang="en">http://retrogod.altervista.org/guppy_4516_cmd.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017569" xml:lang="en">1017569</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0421" xml:lang="en">ADV-2007-0421</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31882" xml:lang="en">guppy-error-code-execution(31882)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3221" xml:lang="en">3221</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple static code injection vulnerabilities in error.php in GuppY 4.5.16 and earlier allow remote attackers to inject arbitrary PHP code into a .inc file in the data/ directory via (1) a REMOTE_ADDR cookie or (2) a cookie specifying an element of the msg array with an error number in the first dimension and 0 in the second dimension, as demonstrated by msg[999][0].</vuln:summary>
  </entry>
  <entry id="CVE-2007-0640">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:zabbix:zabbix:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:zabbix:zabbix:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:zabbix:zabbix:1.1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:zabbix:zabbix:1.1.2</vuln:product>
      <vuln:product>cpe:/a:zabbix:zabbix:1.1.3</vuln:product>
      <vuln:product>cpe:/a:zabbix:zabbix:1.1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0640</vuln:cve-id>
    <vuln:published-datetime>2007-01-31T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:18.923-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22321" xml:lang="en">22321</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0416" xml:lang="en">ADV-2007-0416</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.zabbix.com/rn1.1.5.php" xml:lang="en">http://www.zabbix.com/rn1.1.5.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32038" xml:lang="en">zabbix-snmp-bo(32038)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in ZABBIX before 1.1.5 has unknown impact and attack vectors related to "SNMP IP addresses."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0641">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:shaffer_solutions_corp:dapcnfsd.dll:0.6.4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:shaffer_solutions_corp:dapcnfsd.dll:0.6.4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0641</vuln:cve-id>
    <vuln:published-datetime>2007-01-31T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-13T01:32:32.643-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22301" xml:lang="en">22301</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/data/vulnerabilities/exploits/testlpc.c" xml:lang="en">http://www.securityfocus.com/data/vulnerabilities/exploits/testlpc.c</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the EnumPrintersA function in dapcnfsd.dll 0.6.4.0 in Shaffer Solutions (SSC) DiskAccess NFS Client allows remote attackers to execute arbitrary code via a long argument, an issue similar to CVE-2006-5854 and CVE-2007-0444.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0642">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:rbl:tforum:2.00"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rbl:tforum:2.00</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0642</vuln:cve-id>
    <vuln:published-datetime>2007-01-31T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:40.357-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://forums.avenir-geopolitique.net/viewtopic.php?t=2607" xml:lang="en">http://forums.avenir-geopolitique.net/viewtopic.php?t=2607</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2201" xml:lang="en">2201</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-January/001259.html" xml:lang="en">20070131 Partial source code verify - "RBL - ASP" scripts SQL injection</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458495/100/0/threaded" xml:lang="en">20070127 RBL - ASP (scripts with db) SQL injection</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458560/100/0/threaded" xml:lang="en">20070129 RBL - ASP (scripts with db) SQL injection</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22350" xml:lang="en">22350</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31927" xml:lang="en">rbl-userpass-sql-injection(31927)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in tForum 2.00 in the Raymond BERTHOU script collection (aka RBL - ASP) allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) pass to user_confirm.asp.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0643">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bloodshed_software:dev-c%2b%2b:4.9.9.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bloodshed_software:dev-c%2b%2b:4.9.9.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0643</vuln:cve-id>
    <vuln:published-datetime>2007-01-31T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:02.833-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22315" xml:lang="en">22315</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3229" xml:lang="en">3229</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in Bloodshed Dev-C++ 4.9.9.2 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long line in a .cpp file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0644">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:safari:2.0.4_419.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:safari:2.0.4_419.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0644</vuln:cve-id>
    <vuln:published-datetime>2007-01-31T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:18:26.333-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-02-01T15:05:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.digitalmunition.com/MOAB-30-01-2007.html" xml:lang="en">http://www.digitalmunition.com/MOAB-30-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22326" xml:lang="en">22326</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in Apple Safari 2.0.4 (419.3) allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in filenames that are not properly handled when calling the (1) NSLog and (2) NSBeginAlertSheet Apple AppKit functions.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0645">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:iphoto:6.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:iphoto:6.0.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0645</vuln:cve-id>
    <vuln:published-datetime>2007-01-31T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:18:26.490-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-02-01T15:10:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://projects.info-pull.com/moab/MOAB-30-01-2007.html" xml:lang="en">http://projects.info-pull.com/moab/MOAB-30-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.digitalmunition.com/MOAB-30-01-2007.html" xml:lang="en">http://www.digitalmunition.com/MOAB-30-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22326" xml:lang="en">22326</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in iPhoto 6.0.5 allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling certain Apple AppKit functions.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0646">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.1"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.2"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.3"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.4"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.5"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.7"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.9"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.10"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:apple:imovie:6.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:safari"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:imovie:6.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:safari</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0646</vuln:cve-id>
    <vuln:published-datetime>2007-01-31T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-02-01T15:08:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-134"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305391" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305391</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307041" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307041</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" xml:lang="en">APPLE-SA-2007-04-19</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2007/Nov/msg00002.html" xml:lang="en">APPLE-SA-2007-11-14</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.digitalmunition.com/MOAB-30-01-2007.html" xml:lang="en">http://www.digitalmunition.com/MOAB-30-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22326" xml:lang="en">22326</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/26444" xml:lang="en">26444</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" xml:lang="en">TA07-109A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-319A.html" xml:lang="en">TA07-319A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1470" xml:lang="en">ADV-2007-1470</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/3868" xml:lang="en">ADV-2007-3868</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in iMovie HD 6.0.3, and Safari in Apple Mac OS X 10.4 through 10.4.10, allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling the NSRunCriticalAlertPanel Apple AppKit function.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0647">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0647</vuln:cve-id>
    <vuln:published-datetime>2007-01-31T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:18:26.820-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-02-01T15:08:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.digitalmunition.com/MOAB-30-01-2007.html" xml:lang="en">http://www.digitalmunition.com/MOAB-30-01-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22326" xml:lang="en">22326</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in Help Viewer 3.0.0 allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling the NSBeginAlertSheet Apple AppKit function.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0648">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3%2814%29t"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3%2814%29t2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3%2814%29t4"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3%2814%29t5"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3yg"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3yk"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3ym"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3yq"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3yt"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3yu"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3yx"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4%281%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4%281b%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4%281c%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4%282%29mr"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4%282%29mr1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4%282%29t"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4%282%29t1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4%282%29t2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4%282%29t3"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4%282%29t4"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4%282%29xa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4%282%29xb"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4%282%29xb2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4%283%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4%283%29t2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4%283a%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4%283b%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4%283d%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4%284%29mr"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4%284%29t"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4%284%29t2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4%285%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4%285b%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4%286%29t"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4%286%29t1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4%287%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4%287a%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4%288%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4%289%29t"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4mr"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4sw"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4t"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4xa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4xb"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4xc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4xd"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4xe"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4xg"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4xj"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4xp"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4xt"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:cisco:ios:12.3%2814%29t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3%2814%29t2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3%2814%29t4</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3%2814%29t5</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3yg</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3yk</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3ym</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3yq</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3yt</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3yu</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3yx</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4%281%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4%281b%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4%281c%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4%282%29mr</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4%282%29mr1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4%282%29t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4%282%29t1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4%282%29t2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4%282%29t3</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4%282%29t4</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4%282%29xa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4%282%29xb</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4%282%29xb2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4%283%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4%283%29t2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4%283a%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4%283b%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4%283d%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4%284%29mr</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4%284%29t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4%284%29t2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4%285%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4%285b%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4%286%29t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4%286%29t1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4%287%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4%287a%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4%288%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4%289%29t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4mr</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4sw</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4xa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4xb</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4xc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4xd</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4xe</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4xg</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4xj</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4xp</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4xt</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0648</vuln:cve-id>
    <vuln:published-datetime>2007-01-31T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:38.330-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5138" name="oval:org.mitre.oval:def:5138"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017575" xml:lang="en">1017575</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-air-20070131-sip.shtml" xml:lang="en">http://www.cisco.com/warp/public/707/cisco-air-20070131-sip.shtml</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20070131-sip.shtml" xml:lang="en">20070131 SIP Packet Reloads IOS Devices Not Configured for SIP</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/438176" xml:lang="en">VU#438176</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22330" xml:lang="en">22330</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0428" xml:lang="en">ADV-2007-0428</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31990" xml:lang="en">cisco-sip-packet-dos(31990)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cisco IOS after 12.3(14)T, 12.3(8)YC1, 12.3(8)YG, and 12.4, with voice support and without Session Initiated Protocol (SIP) configured, allows remote attackers to cause a denial of service (crash) by sending a crafted packet to port 5060/UDP.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0649">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:openemr:openemr:2.8.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openemr:openemr:2.8.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0649</vuln:cve-id>
    <vuln:published-datetime>2007-01-31T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:41.027-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>MULTIPLE_INSTANCES</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://attrition.org/pipermail/vim/2007-January/001254.html" xml:lang="en">20070129 [still bogus] V [mike at carstein.kill-9.pl: Re: Open Conference Systems = 2.8.2 Remote File Inclusion] (fwd)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://attrition.org/pipermail/vim/2007-January/001258.html" xml:lang="en">20070131 VERIFY of RFI and XSS in OpenEMR 2.8.2 (was [still bogus] V [mike at carstein.kill-9.pl: Re: Open Conference Systems = 2.8.2 Remote File Inclusion])</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2202" xml:lang="en">2202</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458306/100/0/threaded" xml:lang="en">20070127 Open Conference Systems = 2.8.2 Remote File Inclusion</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458426/100/0/threaded" xml:lang="en">20070127 Re: Open Conference Systems = 2.8.2 Remote File Inclusion</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458456/100/0/threaded" xml:lang="en">20070129 Fake: Open Conference Systems = 2.8.2 Remote File Inclusion</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458476/100/0/threaded" xml:lang="en">20070129 Re: Fake: Open Conference Systems = 2.8.2 Remote File Inclusion</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458486/100/0/threaded" xml:lang="en">20070128 Re: Open Conference Systems = 2.8.2 Remote File Inclusion</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458565/100/0/threaded" xml:lang="en">20070130 Re: Fake: Open Conference Systems = 2.8.2 Remote File Inclusion</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22346" xml:lang="en">22346</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22348" xml:lang="en">22348</vuln:reference>
    </vuln:references>
    <vuln:summary>Variable overwrite vulnerability in interface/globals.php in OpenEMR 2.8.2 and earlier allows remote attackers to overwrite arbitrary program variables and conduct other unauthorized activities, such as conduct (a) remote file inclusion attacks via the srcdir parameter in custom/import_xml.php or (b) cross-site scripting (XSS) attacks via the rootdir parameter in interface/login/login_frame.php, via vectors associated with extract operations on the (1) POST and (2) GET superglobal arrays.  NOTE: this issue was originally disputed before the extract behavior was identified in post-disclosure analysis. Also, the original report identified "Open Conference Systems," but this was an error.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0650">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:makeindex:makeindex:2.14"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:makeindex:makeindex:2.14</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0650</vuln:cve-id>
    <vuln:published-datetime>2007-02-01T14:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:19.110-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200709-17.xml" xml:lang="en">GLSA-200709-17</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200711-34.xml" xml:lang="en">GLSA-200711-34</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200805-13.xml" xml:lang="en">GLSA-200805-13</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:109" xml:lang="en">MDKSA-2007:109</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23872" xml:lang="en">23872</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1706" xml:lang="en">ADV-2007-1706</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=225491" xml:lang="en">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=225491</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32284" xml:lang="en">tetex-makeindex-opensty-bo(32284)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1036" xml:lang="en">https://issues.rpath.com/browse/RPL-1036</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the open_sty function in mkind.c for makeindex 2.14 in teTeX might allow user-assisted remote attackers to overwrite files and possibly execute arbitrary code via a long filename.  NOTE: other overflows exist but might not be exploitable, such as a heap-based overflow in the check_idx function.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0651">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.0.004"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.0.005"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.0.006"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.0.007"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.0.008"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.0.009"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.0.010"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.0.011"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.0.012"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.0.013"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.0.014"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.0.015"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.0.016"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.0.017"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.2a"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.19"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.51"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.52"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.53"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.54"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.72"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.73"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.82"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.83"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.84"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.101"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.102"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.103"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.104"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.105"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.106"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.107"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.108"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.109"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.110"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.111"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.112"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.113"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.114"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.115"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.116"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:2.32"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:2.33"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:2.34"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:2.35"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:2.351"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.0.004</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.0.005</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.0.006</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.0.007</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.0.008</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.0.009</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.0.010</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.0.011</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.0.012</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.0.013</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.0.014</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.0.015</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.0.016</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.0.017</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.1</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.2</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.2a</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.5</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.6</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.7</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.12</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.13</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.14</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.15</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.16</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.17</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.18</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.19</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.51</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.52</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.53</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.54</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.72</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.73</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.82</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.83</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.84</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.101</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.102</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.103</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.104</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.105</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.106</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.107</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.108</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.109</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.110</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.111</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.112</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.113</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.114</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.115</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.116</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:2.0</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:2.1</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:2.2</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:2.32</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:2.33</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:2.34</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:2.35</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:2.351</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0651</vuln:cve-id>
    <vuln:published-datetime>2007-02-15T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:42.200-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2258" xml:lang="en">2258</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mailenable.com/Professional20-ReleaseNotes.txt" xml:lang="en">http://www.mailenable.com/Professional20-ReleaseNotes.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460063/100/0/threaded" xml:lang="en">20070214 Secunia Research: MailEnable Web Mail Client MultipleVulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22554" xml:lang="en">22554</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0595" xml:lang="en">ADV-2007-0595</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32476" xml:lang="en">mailenable-email-messages-xss(32476)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32480" xml:lang="en">mailenable-id-xss(32480)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in MailEnable Professional before 2.37 allow remote attackers to inject arbitrary Javascript script via (1) e-mail messages and (2) the ID parameter to (a) right.asp, (b) Forms/MAI/list.asp, and (c) Forms/VCF/list.asp in mewebmail/base/default/lang/EN/.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0652">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.0.004"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.0.005"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.0.006"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.0.007"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.0.008"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.0.009"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.0.010"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.0.011"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.0.012"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.0.013"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.0.014"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.0.015"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.0.016"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.0.017"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.2a"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.16"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.17"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.18"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.19"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.51"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.52"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.53"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.54"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.72"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.73"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.82"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.83"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.84"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.101"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.102"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.103"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.104"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.105"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.106"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.107"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.108"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.109"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.110"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.111"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.112"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.113"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.114"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.115"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:1.116"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:2.32"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:2.33"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:2.34"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:2.35"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:2.351"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.0.004</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.0.005</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.0.006</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.0.007</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.0.008</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.0.009</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.0.010</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.0.011</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.0.012</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.0.013</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.0.014</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.0.015</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.0.016</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.0.017</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.1</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.2</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.2a</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.5</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.6</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.7</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.12</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.13</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.14</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.15</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.16</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.17</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.18</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.19</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.51</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.52</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.53</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.54</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.72</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.73</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.82</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.83</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.84</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.101</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.102</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.103</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.104</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.105</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.106</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.107</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.108</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.109</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.110</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.111</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.112</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.113</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.114</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.115</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:1.116</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:2.0</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:2.1</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:2.2</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:2.32</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:2.33</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:2.34</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:2.35</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:2.351</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0652</vuln:cve-id>
    <vuln:published-datetime>2007-02-15T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:43.327-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2258" xml:lang="en">2258</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460063/100/0/threaded" xml:lang="en">20070214 Secunia Research: MailEnable Web Mail Client MultipleVulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22554" xml:lang="en">22554</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0595" xml:lang="en">ADV-2007-0595</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site request forgery (CSRF) vulnerability in MailEnable Professional before 2.37 allows remote attackers to modify arbitrary configurations and perform unauthorized actions as arbitrary users via a link or IMG tag.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0653">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:::ia32_64-bit"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:x_multimedia_system:x_multimedia_system:1.2.10"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:x_multimedia_system:x_multimedia_system:1.2.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0653</vuln:cve-id>
    <vuln:published-datetime>2007-03-21T18:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:43.887-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1277" xml:lang="en">DSA-1277</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:071" xml:lang="en">MDKSA-2007:071</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_6_sr.html" xml:lang="en">SUSE-SR:2007:006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/463408/100/0/threaded" xml:lang="en">20070321 Secunia Research: XMMS Integer Overflow and UnderflowVulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23078" xml:lang="en">23078</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-445-1" xml:lang="en">USN-445-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1057" xml:lang="en">ADV-2007-1057</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33205" xml:lang="en">xmms-skinbitmap-code-execution(33205)</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in X MultiMedia System (xmms) 1.2.10, and possibly other versions, allows user-assisted remote attackers to execute arbitrary code via crafted header information in a skin bitmap image, which triggers memory corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0654">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:x_multimedia_system:x_multimedia_system:1.2.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:x_multimedia_system:x_multimedia_system:1.2.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0654</vuln:cve-id>
    <vuln:published-datetime>2007-03-21T18:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:44.827-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1277" xml:lang="en">DSA-1277</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:071" xml:lang="en">MDKSA-2007:071</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_6_sr.html" xml:lang="en">SUSE-SR:2007:006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/463408/100/0/threaded" xml:lang="en">20070321 Secunia Research: XMMS Integer Overflow and UnderflowVulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23078" xml:lang="en">23078</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-445-1" xml:lang="en">USN-445-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1057" xml:lang="en">ADV-2007-1057</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33203" xml:lang="en">xmms-skinbitmap-bo(33203)</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer underflow in X MultiMedia System (xmms) 1.2.10 allows user-assisted remote attackers to execute arbitrary code via crafted header information in a skin bitmap image, which results in a stack-based buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0655">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microworld_technologies:escan:8.0671.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microworld_technologies:escan:8.0671.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0655</vuln:cve-id>
    <vuln:published-datetime>2007-05-02T14:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:19.360-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23759" xml:lang="en">23759</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018007" xml:lang="en">1018007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1609" xml:lang="en">ADV-2007-1609</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/34009" xml:lang="en">escan-mwagent-security-bypass(34009)</vuln:reference>
    </vuln:references>
    <vuln:summary>The MicroWorld Agent service (MWAGENT.EXE) in MicroWorld Technologies eScan 8.0.671.1, and possibly other versions, allows remote or local attackers to gain privileges and execute arbitrary commands by connecting directly to TCP port 2222.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0656">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpbb2-modificat:phpbb2-modificat:0.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb2-modificat:phpbb2-modificat:0.2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpbb2-modificat:phpbb2-modificat:0.1.0</vuln:product>
      <vuln:product>cpe:/a:phpbb2-modificat:phpbb2-modificat:0.2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0656</vuln:cve-id>
    <vuln:published-datetime>2007-02-01T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:02.877-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22320" xml:lang="en">22320</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0422" xml:lang="en">ADV-2007-0422</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31985" xml:lang="en">phpbb2modificat-functions-file-include(31985)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3231" xml:lang="en">3231</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in includes/functions.php in phpBB2-MODificat 0.2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0657">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:alientrap:nexuiz:2.2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:alientrap:nexuiz:2.2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0657</vuln:cve-id>
    <vuln:published-datetime>2007-02-01T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:19.453-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.alientrap.org/devwiki/index.php?n=Nexuiz.Patch" xml:lang="en">http://www.alientrap.org/devwiki/index.php?n=Nexuiz.Patch</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22332" xml:lang="en">22332</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0427" xml:lang="en">ADV-2007-0427</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32040" xml:lang="en">nexuiz-gamedir-information-disclosure(32040)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Nexuiz 2.2.2 allows remote attackers to read and overwrite arbitrary files via the gamedir command.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0658">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.4"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.5"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7.6"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:4.7_rev1.15"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:drupal:5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:textimage:4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:textimage:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:drupal:drupal:4.7</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.1</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.2</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.3</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.4</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.5</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7.6</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:4.7_rev1.15</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:5.0</vuln:product>
      <vuln:product>cpe:/a:drupal:drupal:5.1</vuln:product>
      <vuln:product>cpe:/a:drupal:textimage:4.7</vuln:product>
      <vuln:product>cpe:/a:drupal:textimage:5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0658</vuln:cve-id>
    <vuln:published-datetime>2007-02-01T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:19.517-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://cvs.drupal.org/viewcvs/drupal/contributions/modules/captcha/captcha.module?r1=1.25.2.1&amp;r2=1.25.2.2" xml:lang="en">http://cvs.drupal.org/viewcvs/drupal/contributions/modules/captcha/captcha.module?r1=1.25.2.1&amp;r2=1.25.2.2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://cvs.drupal.org/viewcvs/drupal/contributions/modules/textimage/captcha.inc?r1=1.1&amp;r2=1.1.2.1" xml:lang="en">http://cvs.drupal.org/viewcvs/drupal/contributions/modules/textimage/captcha.inc?r1=1.1&amp;r2=1.1.2.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://drupal.org/node/114364" xml:lang="en">http://drupal.org/node/114364</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://drupal.org/node/114519" xml:lang="en">http://drupal.org/node/114519</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22329" xml:lang="en">22329</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0431" xml:lang="en">ADV-2007-0431</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31984" xml:lang="en">textimage-captcha-security-bypass(31984)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31994" xml:lang="en">captcha-response-security-bypass(31994)</vuln:reference>
    </vuln:references>
    <vuln:summary>The (1) Textimage 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 module for Drupal and the (2) Captcha 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 module for Drupal allow remote attackers to bypass the CAPTCHA test via an empty captcha element in $_SESSION.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0659">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:modxcms:filedownload:1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:modxcms:filedownload:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:modxcms:filedownload:1.7</vuln:product>
      <vuln:product>cpe:/a:modxcms:filedownload:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0659</vuln:cve-id>
    <vuln:published-datetime>2007-02-01T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:50:29.220-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://modxcms.com/forums/index.php/topic,10470.0.html" xml:lang="en">http://modxcms.com/forums/index.php/topic,10470.0.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.muddydogpaws.com/Home.html" xml:lang="en">http://www.muddydogpaws.com/Home.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22327" xml:lang="en">22327</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0426" xml:lang="en">ADV-2007-0426</vuln:reference>
    </vuln:references>
    <vuln:summary>download.php in the MuddyDogPaws FileDownload snippet before 2.5 for MODx allows remote attackers to download arbitrary files, as demonstrated by downloading config.inc.php to obtain database credentials.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0660">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:dotnetnuke:dotnetnuke_iframe:03.01.01"/>
        <cpe-lang:fact-ref name="cpe:/a:dotnetnuke:dotnetnuke_iframe:03.02.00"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:dotnetnuke:dotnetnuke_iframe:03.01.01</vuln:product>
      <vuln:product>cpe:/a:dotnetnuke:dotnetnuke_iframe:03.02.00</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0660</vuln:cve-id>
    <vuln:published-datetime>2007-02-01T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:19.577-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.dotnetnuke.com/Default.aspx?tabid=825&amp;EntryID=1278" xml:lang="en">http://www.dotnetnuke.com/Default.aspx?tabid=825&amp;EntryID=1278</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22334" xml:lang="en">22334</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0433" xml:lang="en">ADV-2007-0433</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32037" xml:lang="en">dotnetnuke-iframe-unspecified-xss(32037)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the IFrame module before 03.02.01 for DotNetNuke (DNN) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "Pass through values."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0661">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:intel:enterprise_southbridge_2_bmc"/>
        <cpe-lang:fact-ref name="cpe:/h:intel:enterprise_southbridge_bmc:::oem"/>
        <cpe-lang:fact-ref name="cpe:/h:intel:server_board_s5000pal"/>
        <cpe-lang:fact-ref name="cpe:/h:intel:server_board_s5000psl"/>
        <cpe-lang:fact-ref name="cpe:/h:intel:server_board_s5000vcl"/>
        <cpe-lang:fact-ref name="cpe:/h:intel:server_board_s5000vsa"/>
        <cpe-lang:fact-ref name="cpe:/h:intel:server_board_s5000xal"/>
        <cpe-lang:fact-ref name="cpe:/h:intel:server_board_s5000xvn"/>
        <cpe-lang:fact-ref name="cpe:/h:intel:server_board_sc5400ra"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:intel:enterprise_southbridge_2_bmc</vuln:product>
      <vuln:product>cpe:/h:intel:enterprise_southbridge_bmc:::oem</vuln:product>
      <vuln:product>cpe:/h:intel:server_board_s5000pal</vuln:product>
      <vuln:product>cpe:/h:intel:server_board_s5000psl</vuln:product>
      <vuln:product>cpe:/h:intel:server_board_s5000vcl</vuln:product>
      <vuln:product>cpe:/h:intel:server_board_s5000vsa</vuln:product>
      <vuln:product>cpe:/h:intel:server_board_s5000xal</vuln:product>
      <vuln:product>cpe:/h:intel:server_board_s5000xvn</vuln:product>
      <vuln:product>cpe:/h:intel:server_board_sc5400ra</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0661</vuln:cve-id>
    <vuln:published-datetime>2007-02-01T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:50:29.547-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.4</cvss:score>
        <cvss:access-vector>ADJACENT_NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://lz1.intel.com/psirt/advisory.aspx?intelid=INTEL-SA-00012&amp;languageid=en-fr" xml:lang="en">http://lz1.intel.com/psirt/advisory.aspx?intelid=INTEL-SA-00012&amp;languageid=en-fr</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22341" xml:lang="en">22341</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0432" xml:lang="en">ADV-2007-0432</vuln:reference>
    </vuln:references>
    <vuln:summary>Intel Enterprise Southbridge 2 Baseboard Management Controller (BMC), Intel Server Boards 5000XAL, S5000PAL, S5000PSL, S5000XVN, S5000VCL, S5000VSA, SC5400RA, and OEM Firmware for Intel Enterprise Southbridge Baseboard Management Controller before 20070119, when Intelligent Platform Management Interface (IPMI) is enabled, allow remote attackers to connect and issue arbitrary IPMI commands, possibly triggering a denial of service.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0662">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:hailboards:hailboards:1.2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hailboards:hailboards:1.2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0662</vuln:cve-id>
    <vuln:published-datetime>2007-02-01T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:02.927-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22333" xml:lang="en">22333</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0450" xml:lang="en">ADV-2007-0450</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31997" xml:lang="en">hailboards-usercpviewprofile-file-include(31997)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3236" xml:lang="en">3236</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in includes/usercp_viewprofile.php in Hailboards 1.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0663">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:eclectic_designs:cascadianfaq:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:eclectic_designs:cascadianfaq:4.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:eclectic_designs:cascadianfaq:4.0</vuln:product>
      <vuln:product>cpe:/a:eclectic_designs:cascadianfaq:4.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0663</vuln:cve-id>
    <vuln:published-datetime>2007-02-01T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:50:29.783-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0424" xml:lang="en">ADV-2007-0424</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in index.php in Eclectic Designs CascadianFAQ 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the qid parameter, a different vector than CVE-2007-0631.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0664">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:acme_labs:thttpd:2.24"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:acme_labs:thttpd:2.24</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0664</vuln:cve-id>
    <vuln:published-datetime>2007-02-02T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:41:25.063-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://bugs.gentoo.org/show_bug.cgi?id=142047" xml:lang="en">http://bugs.gentoo.org/show_bug.cgi?id=142047</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200701-28.xml" xml:lang="en">GLSA-200701-28</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22349" xml:lang="en">22349</vuln:reference>
    </vuln:references>
    <vuln:summary>thttpd before 2.25b-r6 in Gentoo Linux is started from the system root directory (/) by the Gentoo baselayout 1.12.6 package, which allows remote attackers to read arbitrary files.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0665">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ipswitch:ws_ftp_pro:2007"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ipswitch:ws_ftp_pro:2007</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0665</vuln:cve-id>
    <vuln:published-datetime>2007-02-02T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:45.683-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458293/100/0/threaded" xml:lang="en">20070126 WS_FTP 2007 Professional SCP handling format string vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22275" xml:lang="en">22275</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31865" xml:lang="en">wsftp-scphandler-format-string(31865)</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in the SCP module in Ipswitch WS_FTP 2007 Professional might allow remote attackers to execute arbitrary commands via format string specifiers in the filename, related to the SHELL WS_FTP script command.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0666">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ipswitch:ws_ftp_server:5.04"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ipswitch:ws_ftp_server:5.04</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0666</vuln:cve-id>
    <vuln:published-datetime>2007-02-02T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:45.980-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458774/100/0/threaded" xml:lang="en">20070201 Ipswitch WS_FTP Server 5.04 multiple arbitrary code execution vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458932/100/0/threaded" xml:lang="en">20070202 Re: Ipswitch WS_FTP Server 5.04 multiple arbitrary code execution vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458942/100/0/threaded" xml:lang="en">20070202 Re[2]: Ipswitch WS_FTP Server 5.04 multiple arbitrary code execution vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459023/100/0/threaded" xml:lang="en">20070202 Re: Re: Ipswitch WS_FTP Server 5.04 multiple arbitrary code execution vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32176" xml:lang="en">wsftp-iftpaddu-privilege-escalation(32176)</vuln:reference>
    </vuln:references>
    <vuln:summary>Ipswitch WS_FTP Server 5.04 allows FTP site administrators to execute arbitrary code on the system via a long input string to the (1) iFTPAddU or (2) iFTPAddH file, or to a (3) edition module.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0667">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ledgersmb:ledgersmb:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sql-ledger:sql-ledger:2.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:sql-ledger:sql-ledger:2.6.17"/>
        <cpe-lang:fact-ref name="cpe:/a:sql-ledger:sql-ledger:2.6.18"/>
        <cpe-lang:fact-ref name="cpe:/a:sql-ledger:sql-ledger:2.6.19"/>
        <cpe-lang:fact-ref name="cpe:/a:sql-ledger:sql-ledger:2.6.21"/>
        <cpe-lang:fact-ref name="cpe:/a:sql-ledger:sql-ledger:2.6.25"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ledgersmb:ledgersmb:1.1.1</vuln:product>
      <vuln:product>cpe:/a:sql-ledger:sql-ledger:2.4.7</vuln:product>
      <vuln:product>cpe:/a:sql-ledger:sql-ledger:2.6.17</vuln:product>
      <vuln:product>cpe:/a:sql-ledger:sql-ledger:2.6.18</vuln:product>
      <vuln:product>cpe:/a:sql-ledger:sql-ledger:2.6.19</vuln:product>
      <vuln:product>cpe:/a:sql-ledger:sql-ledger:2.6.21</vuln:product>
      <vuln:product>cpe:/a:sql-ledger:sql-ledger:2.6.25</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0667</vuln:cve-id>
    <vuln:published-datetime>2007-02-02T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:46.623-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2217" xml:lang="en">2217</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458464/100/0/threaded" xml:lang="en">20070127 Arbitrary Code Execution in SQL-Ledger and LedgerSMB through redirects</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459264/100/0/threaded" xml:lang="en">20070206 Unofficial SQL-Ledger patch for CVE-2007-0667</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22295" xml:lang="en">22295</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0407" xml:lang="en">ADV-2007-0407</vuln:reference>
    </vuln:references>
    <vuln:summary>The redirect function in Form.pm for (1) LedgerSMB before 1.1.5 and (2) SQL-Ledger allows remote authenticated users to execute arbitrary code via redirects, related to callbacks, a different issue than CVE-2006-5872.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0668">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:10.0::sparc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:10.0::sparc</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0668</vuln:cve-id>
    <vuln:published-datetime>2007-02-02T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:38.407-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1372" name="oval:org.mitre.oval:def:1372"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017582" xml:lang="en">1017582</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102699-1" xml:lang="en">102699</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22364" xml:lang="en">22364</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0462" xml:lang="en">ADV-2007-0462</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32140" xml:lang="en">solaris-loopbackfs-dos(32140)</vuln:reference>
    </vuln:references>
    <vuln:summary>The Loopback Filesystem (LOFS) in Sun Solaris 10 allows local users in a non-global zone to move and rename files in a read-only filesystem, which could lead to a denial of service.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0669">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:twiki:twiki:4.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:twiki:twiki:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:twiki:twiki:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:twiki:twiki:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:twiki:twiki:4.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:twiki:twiki:4.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:twiki:twiki:4.1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:twiki:twiki:4.0.0</vuln:product>
      <vuln:product>cpe:/a:twiki:twiki:4.0.1</vuln:product>
      <vuln:product>cpe:/a:twiki:twiki:4.0.2</vuln:product>
      <vuln:product>cpe:/a:twiki:twiki:4.0.3</vuln:product>
      <vuln:product>cpe:/a:twiki:twiki:4.0.4</vuln:product>
      <vuln:product>cpe:/a:twiki:twiki:4.0.5</vuln:product>
      <vuln:product>cpe:/a:twiki:twiki:4.1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0669</vuln:cve-id>
    <vuln:published-datetime>2007-02-08T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:19.860-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VULNWATCH</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/vulnwatch/2007-q1/0033.html" xml:lang="en">20070208 TWiki Security Alert: Arbitrary code execution in session files (CVE-2007-0669)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2007-0669" xml:lang="en">http://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2007-0669</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/584436" xml:lang="en">VU#584436</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OPENPKG</vuln:source>
      <vuln:reference href="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.009.html" xml:lang="en">OpenPKG-SA-2007.009</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22378" xml:lang="en">22378</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0544" xml:lang="en">ADV-2007-0544</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32389" xml:lang="en">twiki-cgisession-code-execution(32389)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Twiki 4.0.0 through 4.1.0 allows local users to execute arbitrary Perl code via unknown vectors related to CGI session files.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0670">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:5.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:5.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0670</vuln:cve-id>
    <vuln:published-datetime>2007-02-02T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:19.923-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="ftp://aix.software.ibm.com/aix/efixes/security/README" xml:lang="en">ftp://aix.software.ibm.com/aix/efixes/security/README</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017583" xml:lang="en">1017583</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017607" xml:lang="en">1017607</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22370" xml:lang="en">22370</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22456" xml:lang="en">22456</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0471" xml:lang="en">ADV-2007-0471</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?uid=isg1IY94301" xml:lang="en">IY94301</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?uid=isg1IY94368" xml:lang="en">IY94368</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32184" xml:lang="en">aix-rdist-bo(32184)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in bos.rte.libc in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code via the "r-commands", possibly including (1) rdist, (2) rsh, (3) rcp, (4) rsync, and (5) rlogin.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0671">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:access:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:access:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:access:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2004::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel_viewer:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:frontpage:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:frontpage:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:frontpage:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:infopath:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2004::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:onenote:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:powerpoint:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:powerpoint:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:powerpoint:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:powerpoint:2004::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:project:2000:sr1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:project:2002:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:project:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:publisher:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:publisher:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:publisher:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visio:2002:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visio:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word_viewer:2003"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:access:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:access:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:access:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2004::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel_viewer:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:frontpage:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:frontpage:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:frontpage:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:infopath:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2004::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:onenote:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:powerpoint:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:powerpoint:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:powerpoint:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:powerpoint:2004::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:project:2000:sr1</vuln:product>
      <vuln:product>cpe:/a:microsoft:project:2002:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:project:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:publisher:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:publisher:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:publisher:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:visio:2002:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:visio:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:word_viewer:2003</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0671</vuln:cve-id>
    <vuln:published-datetime>2007-02-02T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:42:45.297-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A301" name="oval:org.mitre.oval:def:301"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017584" xml:lang="en">1017584</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://vil.nai.com/vil/content/v_141393.htm" xml:lang="en">http://vil.nai.com/vil/content/v_141393.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.avertlabs.com/research/blog/?p=191" xml:lang="en">http://www.avertlabs.com/research/blog/?p=191</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/613740" xml:lang="en">VU#613740</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/advisory/932553.mspx" xml:lang="en">http://www.microsoft.com/technet/security/advisory/932553.mspx</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22383" xml:lang="en">22383</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" xml:lang="en">TA07-044A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0463" xml:lang="en">ADV-2007-0463</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-015" xml:lang="en">MS07-015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32178" xml:lang="en">office-unspecified-code-execution(32178)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0672">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ca:brightstor_arcserve_backup_laptops_desktops:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:brightstor_arcserve_backup_laptops_desktops:11.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:brightstor_arcserve_backup_laptops_desktops:11.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:business_protection_suite:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:business_protection_suite:2.0::microsoft_sbs_premium"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:business_protection_suite:2.0::microsoft_sbs_standard"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:desktop_management_suite:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:desktop_management_suite:11.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:desktop_protection_suite:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ca:brightstor_arcserve_backup_laptops_desktops:11.0</vuln:product>
      <vuln:product>cpe:/a:ca:brightstor_arcserve_backup_laptops_desktops:11.1</vuln:product>
      <vuln:product>cpe:/a:ca:brightstor_arcserve_backup_laptops_desktops:11.1:sp1</vuln:product>
      <vuln:product>cpe:/a:ca:business_protection_suite:2.0</vuln:product>
      <vuln:product>cpe:/a:ca:business_protection_suite:2.0::microsoft_sbs_premium</vuln:product>
      <vuln:product>cpe:/a:ca:business_protection_suite:2.0::microsoft_sbs_standard</vuln:product>
      <vuln:product>cpe:/a:ca:desktop_management_suite:11.0</vuln:product>
      <vuln:product>cpe:/a:ca:desktop_management_suite:11.1</vuln:product>
      <vuln:product>cpe:/a:ca:desktop_protection_suite:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0672</vuln:cve-id>
    <vuln:published-datetime>2007-02-02T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:46.980-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://supportconnectw.ca.com/public/sams/lifeguard/infodocs/babldimpsec-notice.asp" xml:lang="en">http://supportconnectw.ca.com/public/sams/lifeguard/infodocs/babldimpsec-notice.asp</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458653/100/0/threaded" xml:lang="en">20070131 Remote Unauthenticated Resource Exhaustion CA Mobile BackupService</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22339" xml:lang="en">22339</vuln:reference>
    </vuln:references>
    <vuln:summary>LGSERVER.EXE in BrightStor Mobile Backup 4.0 allows remote attackers to cause a denial of service (disk consumption and daemon hang) via a value of 0xFFFFFF7F at a certain point in an authentication negotiation packet, which writes a large amount of data to a .USX file in CA_BABLDdata\Server\data\transfer\.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0673">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ca:brightstor_arcserve_backup_laptops_desktops:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:brightstor_arcserve_backup_laptops_desktops:11.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:brightstor_arcserve_backup_laptops_desktops:11.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:business_protection_suite:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:business_protection_suite:2.0::microsoft_sbs_premium"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:business_protection_suite:2.0::microsoft_sbs_standard"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:desktop_management_suite:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:desktop_management_suite:11.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:desktop_protection_suite:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ca:brightstor_arcserve_backup_laptops_desktops:11.0</vuln:product>
      <vuln:product>cpe:/a:ca:brightstor_arcserve_backup_laptops_desktops:11.1</vuln:product>
      <vuln:product>cpe:/a:ca:brightstor_arcserve_backup_laptops_desktops:11.1:sp1</vuln:product>
      <vuln:product>cpe:/a:ca:business_protection_suite:2.0</vuln:product>
      <vuln:product>cpe:/a:ca:business_protection_suite:2.0::microsoft_sbs_premium</vuln:product>
      <vuln:product>cpe:/a:ca:business_protection_suite:2.0::microsoft_sbs_standard</vuln:product>
      <vuln:product>cpe:/a:ca:desktop_management_suite:11.0</vuln:product>
      <vuln:product>cpe:/a:ca:desktop_management_suite:11.1</vuln:product>
      <vuln:product>cpe:/a:ca:desktop_protection_suite:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0673</vuln:cve-id>
    <vuln:published-datetime>2007-02-02T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:47.200-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2218" xml:lang="en">2218</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://supportconnectw.ca.com/public/sams/lifeguard/infodocs/babldimpsec-notice.asp" xml:lang="en">http://supportconnectw.ca.com/public/sams/lifeguard/infodocs/babldimpsec-notice.asp</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458650/100/0/threaded" xml:lang="en">20070131 Remote DOS BrightStor ARCserve Backup for Laptops &amp; Desktops</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22337" xml:lang="en">22337</vuln:reference>
    </vuln:references>
    <vuln:summary>LGSERVER.EXE in BrightStor ARCserve Backup for Laptops &amp; Desktops r11.1 allows remote attackers to cause a denial of service (daemon crash) via a value of 0xFFFFFFFF at a certain point in an authentication negotiation packet, which results in an out-of-bounds read.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0674">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_mobile"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_mobile:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_mobile:2003"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_mobile:2003_se"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_mobile</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_mobile:5.0</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_mobile:2003</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_mobile:2003_se</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0674</vuln:cve-id>
    <vuln:published-datetime>2007-02-02T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:20.047-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://blog.trendmicro.com/trend-micro-finds-more-windows-mobile-flaws/" xml:lang="en">http://blog.trendmicro.com/trend-micro-finds-more-windows-mobile-flaws/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22343" xml:lang="en">22343</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0434" xml:lang="en">ADV-2007-0434</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32002" xml:lang="en">picturesvideos-jpeg-dos(32002)</vuln:reference>
    </vuln:references>
    <vuln:summary>Pictures and Videos on Windows Mobile 5.0 and Windows Mobile 2003 and 2003SE for Smartphones and PocketPC allows user-assisted remote attackers to cause a denial of service (device hang) via a malformed JPEG file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0675">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:::32_bit"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_vista:::32_bit</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0675</vuln:cve-id>
    <vuln:published-datetime>2007-02-02T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:42:46.720-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5489" name="oval:org.mitre.oval:def:5489"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://blogs.technet.com/msrc/archive/2007/01/31/issue-regarding-windows-vista-speech-recognition.aspx" xml:lang="en">http://blogs.technet.com/msrc/archive/2007/01/31/issue-regarding-windows-vista-speech-recognition.aspx</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.immunitysec.com/pipermail/dailydave/2007-January/004003.html" xml:lang="en">[dailydave] 20070130 Vista speach recognition</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.immunitysec.com/pipermail/dailydave/2007-January/004005.html" xml:lang="en">[dailydave] 20070130 Vista speach recognition</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.immunitysec.com/pipermail/dailydave/2007-January/004007.html" xml:lang="en">[dailydave] 20070130 Vista speach recognition</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.immunitysec.com/pipermail/dailydave/2007-January/004012.html" xml:lang="en">[dailydave] 20070131 Vista speach recognition</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=121380194923597&amp;w=2" xml:lang="en">HPSBST02344</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22359" xml:lang="en">22359</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1020232" xml:lang="en">1020232</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-162B.html" xml:lang="en">TA08-162B</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/1779/references" xml:lang="en">ADV-2008-1779</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-032" xml:lang="en">MS08-032</vuln:reference>
    </vuln:references>
    <vuln:summary>A certain ActiveX control in sapi.dll (aka the Speech API) in Speech Components in Microsoft Windows Vista, when the Speech Recognition feature is enabled, allows user-assisted remote attackers to delete arbitrary files, and conduct other unauthorized activities, via a web page with an embedded sound object that contains voice commands to an enabled microphone, allowing for interaction with Windows Explorer.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0676">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:exo:exophpdesk:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:exo:exophpdesk:1.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:exo:exophpdesk:1.2</vuln:product>
      <vuln:product>cpe:/a:exo:exophpdesk:1.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0676</vuln:cve-id>
    <vuln:published-datetime>2007-02-02T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:02.987-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22338" xml:lang="en">22338</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0452" xml:lang="en">ADV-2007-0452</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31998" xml:lang="en">exophpdesk-faq-sql-injection(31998)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3234" xml:lang="en">3234</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in faq.php in ExoPHPDesk 1.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0677">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cronosys:cadre_php_framework:22020724"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cronosys:cadre_php_framework:22020724</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0677</vuln:cve-id>
    <vuln:published-datetime>2007-02-02T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:47.513-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://echo.or.id/adv/adv63-y3dips-2007.txt" xml:lang="en">http://echo.or.id/adv/adv63-y3dips-2007.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2215" xml:lang="en">2215</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458681/100/0/threaded" xml:lang="en">20070131 [ECHO_ADV_63$2007] Cadre remote file inclusion</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22336" xml:lang="en">22336</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0449" xml:lang="en">ADV-2007-0449</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32005" xml:lang="en">cadre-classquickconfigbrowser-file-include(32005)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3237" xml:lang="en">3237</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in fw/class.Quick_Config_Browser.php in Cadre PHP Framework 20020724 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[config][framework_path] parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0678">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:fullaspsite:asp_hosting_site"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:fullaspsite:asp_hosting_site</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0678</vuln:cve-id>
    <vuln:published-datetime>2007-02-02T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:03.113-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22347" xml:lang="en">22347</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0453" xml:lang="en">ADV-2007-0453</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32020" xml:lang="en">fullaspsite-windows-sql-injection(32020)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3233" xml:lang="en">3233</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in windows.asp in Fullaspsite Asp Hosting Sitesi allows remote attackers to execute arbitrary SQL commands via the kategori_id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0679">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nicolas_grandjean:phpmyring:4.1.0b"/>
        <cpe-lang:fact-ref name="cpe:/a:nicolas_grandjean:phpmyring:4.1.1b"/>
        <cpe-lang:fact-ref name="cpe:/a:nicolas_grandjean:phpmyring:4.1.2b"/>
        <cpe-lang:fact-ref name="cpe:/a:nicolas_grandjean:phpmyring:4.1.3b"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nicolas_grandjean:phpmyring:4.1.0b</vuln:product>
      <vuln:product>cpe:/a:nicolas_grandjean:phpmyring:4.1.1b</vuln:product>
      <vuln:product>cpe:/a:nicolas_grandjean:phpmyring:4.1.2b</vuln:product>
      <vuln:product>cpe:/a:nicolas_grandjean:phpmyring:4.1.3b</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0679</vuln:cve-id>
    <vuln:published-datetime>2007-02-02T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:03.177-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22345" xml:lang="en">22345</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0448" xml:lang="en">ADV-2007-0448</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32033" xml:lang="en">phpmyring-leslangues-file-include(32033)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3238" xml:lang="en">3238</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in lang/leslangues.php in Nicolas Grandjean PHPMyRing 4.1.3b and earlier allows remote attackers to execute arbitrary PHP code via a URL in the fichier parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0680">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpbb_tweaked:phpbb_tweaked:1"/>
        <cpe-lang:fact-ref name="cpe:/a:phpbb_tweaked:phpbb_tweaked:3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpbb_tweaked:phpbb_tweaked:1</vuln:product>
      <vuln:product>cpe:/a:phpbb_tweaked:phpbb_tweaked:3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0680</vuln:cve-id>
    <vuln:published-datetime>2007-02-02T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:03.223-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22344" xml:lang="en">22344</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0451" xml:lang="en">ADV-2007-0451</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.xoron.info/bugs/phpbbtweaked.txt" xml:lang="en">http://www.xoron.info/bugs/phpbbtweaked.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32024" xml:lang="en">phpbbtweaked-functions-file-include(32024)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3235" xml:lang="en">3235</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in includes/functions.php in Phpbb Tweaked 3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0681">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:extcalendar:extcalendar:2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:extcalendar:extcalendar:2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0681</vuln:cve-id>
    <vuln:published-datetime>2007-02-02T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:03.300-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32035" xml:lang="en">extcalendar-profile-security-bypass(32035)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3239" xml:lang="en">3239</vuln:reference>
    </vuln:references>
    <vuln:summary>profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original password, and possibly perform other unauthorized actions, via modified values to register.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0682">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:jv2:folder_gallery:3.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:jv2:folder_gallery:3.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0682</vuln:cve-id>
    <vuln:published-datetime>2007-02-02T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:03.363-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22354" xml:lang="en">22354</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0447" xml:lang="en">ADV-2007-0447</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32043" xml:lang="en">jv2gallery-template-file-include(32043)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3240" xml:lang="en">3240</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in theme/include_mode/template.php in JV2 Folder Gallery 3.0.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the galleryfilesdir parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0683">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:omegaboard_project:omegaboard:1.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:omegaboard_project:omegaboard:1.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:omegaboard_project:omegaboard:1.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:omegaboard_project:omegaboard:1.0:beta4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:omegaboard_project:omegaboard:1.0:beta1</vuln:product>
      <vuln:product>cpe:/a:omegaboard_project:omegaboard:1.0:beta2</vuln:product>
      <vuln:product>cpe:/a:omegaboard_project:omegaboard:1.0:beta3</vuln:product>
      <vuln:product>cpe:/a:omegaboard_project:omegaboard:1.0:beta4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0683</vuln:cve-id>
    <vuln:published-datetime>2007-02-02T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-11-29T10:45:54.473-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2018-11-19T11:09:14.727-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=117036933022782&amp;w=2" xml:lang="en">20070201 Omegaboard v1.0b4 (phpbb_root_path) Remote File Include Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458825/100/0/threaded" xml:lang="en">20070201 Omegaboard v1.0b4 (phpbb_root_path) Remote File Include Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22355" xml:lang="en">22355</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32057" xml:lang="en">omegaboard-functions-file-include(32057)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3242" xml:lang="en">3242</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in includes/functions.php in Omegaboard 1.0beta4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0684">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cerulean_portal_system:cerulean_portal_system:0.7b"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cerulean_portal_system:cerulean_portal_system:0.7b</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0684</vuln:cve-id>
    <vuln:published-datetime>2007-02-02T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:48.700-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458824/100/0/threaded" xml:lang="en">20070201 Cerulean Portal System (phpbb_root_path) Remote File Include Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22356" xml:lang="en">22356</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0444" xml:lang="en">ADV-2007-0444</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.xoron.info/bugs/ceruleanportalsystem-html.txt" xml:lang="en">http://www.xoron.info/bugs/ceruleanportalsystem-html.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.xoron.info/bugs/ceruleanportalsystem-perl.txt" xml:lang="en">http://www.xoron.info/bugs/ceruleanportalsystem-perl.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32058" xml:lang="en">cerulean-portal-file-include(32058)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3243" xml:lang="en">3243</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in portal.php in Cerulean Portal System 0.7b allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0685">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_mobile"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_mobile:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_mobile:2003"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_mobile:2003_se"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_mobile</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_mobile:5.0</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_mobile:2003</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_mobile:2003_se</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0685</vuln:cve-id>
    <vuln:published-datetime>2007-02-02T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:20.593-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://blog.trendmicro.com/trend-micro-finds-more-windows-mobile-flaws/" xml:lang="en">http://blog.trendmicro.com/trend-micro-finds-more-windows-mobile-flaws/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22343" xml:lang="en">22343</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0434" xml:lang="en">ADV-2007-0434</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32001" xml:lang="en">ie-mobile-unspecified-dos(32001)</vuln:reference>
    </vuln:references>
    <vuln:summary>Internet Explorer on Windows Mobile 5.0 and Windows Mobile 2003 and 2003SE for Smartphones and PocketPC allows attackers to cause a denial of service (application crash and device instability) via unspecified vectors, possibly related to a buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0686">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:intel:2200bg_proset_wireless:9.0.3.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:intel:2200bg_proset_wireless:9.0.3.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0686</vuln:cve-id>
    <vuln:published-datetime>2007-02-02T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:03.567-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3224" xml:lang="en">3224</vuln:reference>
    </vuln:references>
    <vuln:summary>The Intel 2200BG 802.11 Wireless Mini-PCI driver 9.0.3.9 (w29n51.sys) allows remote attackers to cause a denial of service (system crash) via crafted disassociation packets, which triggers memory corruption of "internal kernel structures," a different vulnerability than CVE-2006-6651.  NOTE: this issue might overlap CVE-2006-3992.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0687">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:michelle:l2j_dropcalc:4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:michelle:l2j_dropcalc:4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0687</vuln:cve-id>
    <vuln:published-datetime>2007-02-02T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:03.627-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22335" xml:lang="en">22335</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32003" xml:lang="en">l2j-isearch-sql-injection(32003)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3232" xml:lang="en">3232</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in i-search.php in Michelle's L2J Dropcalc 4 and earlier allows remote authenticated users to execute arbitrary SQL commands via the itemid parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0688">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:hunkaray_duyuru:scripti"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hunkaray_duyuru:scripti</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0688</vuln:cve-id>
    <vuln:published-datetime>2007-02-02T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:49.183-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/470744/100/0/threaded" xml:lang="en">20070607 H&amp;uuml;nkaray Duyuru Script Remote SQL &amp;#304;njection</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/24367" xml:lang="en">24367</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0446" xml:lang="en">ADV-2007-0446</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32042" xml:lang="en">hds-oku-sql-injection(32042)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3241" xml:lang="en">3241</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in oku.asp in Hunkaray Duyuru Scripti allows remote attackers to execute arbitrary SQL commands via the id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0689">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mybb:mybb:1.2.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mybb:mybb:1.2.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0689</vuln:cve-id>
    <vuln:published-datetime>2007-05-14T17:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:49.700-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://marc.info/?l=full-disclosure&amp;m=117909973216181&amp;w=2" xml:lang="en">20070513 MyBB version 1.2.4 Multiple Path Disclosure Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.netvigilance.com/advisory0017" xml:lang="en">http://www.netvigilance.com/advisory0017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/468549/100/0/threaded" xml:lang="en">20070513 MyBB version 1.2.4 Multiple Path Disclosure Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/34336" xml:lang="en">mybb-eventmembercaptcha-info-disclosure(34336)</vuln:reference>
    </vuln:references>
    <vuln:summary>MyBB 1.2.4 allows remote attackers to obtain sensitive information via the (1) action[] parameter to member.php, (2) imagehash[] parameter to captcha.php, and (3) a direct request to inc/datahandlers/event.php, which reveal the installation path in the resulting error message.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0690">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:myevent:myevent:1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:myevent:myevent:1.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0690</vuln:cve-id>
    <vuln:published-datetime>2007-05-30T16:30:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:50.153-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2744" xml:lang="en">2744</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/469831/100/0/threaded" xml:lang="en">20070528 myEvent version 1.6 Multiple Path Disclosure Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/34542" xml:lang="en">myevent-myevent-login-path-disclosure(34542)</vuln:reference>
    </vuln:references>
    <vuln:summary>myEvent 1.6 allows remote attackers to obtain sensitive information via (1) a Log In action without a password to login.php, or an invalid (2) view[] or (3) monthno[] parameter to myevent.php, which reveals the path in various error messages.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0691">
    <vuln:cve-id>CVE-2007-0691</vuln:cve-id>
    <vuln:published-datetime>2007-05-08T06:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:49:51.633-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2007-2066.  Reason: This candidate is a duplicate of CVE-2007-2066.  Notes: All CVE users should reference CVE-2007-2066 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0692">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:dgnews:dgnews:2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:dgnews:dgnews:2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0692</vuln:cve-id>
    <vuln:published-datetime>2007-05-30T16:30:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:50.577-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2741" xml:lang="en">2741</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/469826/100/0/threaded" xml:lang="en">20070528 DGNews version 2.1 Path Disclosure Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/34540" xml:lang="en">dgnews-news-path-disclosure(34540)</vuln:reference>
    </vuln:references>
    <vuln:summary>DGNews 2.1 allows remote attackers to obtain sensitive information via a fullnews request to news.php with an invalid newsid parameter, and other unspecified vectors, which reveal the path in various error messages.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0693">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:dian_gemilang:dgnews:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:dian_gemilang:dgnews:2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:dian_gemilang:dgnews:1.5.1</vuln:product>
      <vuln:product>cpe:/a:dian_gemilang:dgnews:2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0693</vuln:cve-id>
    <vuln:published-datetime>2007-05-30T16:30:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:50.933-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2740" xml:lang="en">2740</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/469828/100/0/threaded" xml:lang="en">20070528 DGNews version 2.1 SQL Injection Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/24201" xml:lang="en">24201</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1981" xml:lang="en">ADV-2007-1981</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/34539" xml:lang="en">dgnews-news-sql-injection(34539)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in news.php in DGNews 2.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter in a newslist action.  NOTE: this issue can produce resultant cross-site scripting (XSS).</vuln:summary>
  </entry>
  <entry id="CVE-2007-0694">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:dian_gemilang:dgnews:2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:dian_gemilang:dgnews:2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0694</vuln:cve-id>
    <vuln:published-datetime>2007-05-30T16:30:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:51.450-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2739" xml:lang="en">2739</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/469829/100/0/threaded" xml:lang="en">20070528 DGNews version 2.1 XSS Attack Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/24200" xml:lang="en">24200</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1981" xml:lang="en">ADV-2007-1981</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/34537" xml:lang="en">dgnews-footer-xss(34537)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in footer.php in DGNews 2.1 allows remote attackers to inject arbitrary web script or HTML via the copyright parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0695">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:free_lan_intra_internet_portal:free_lan_intra_internet_portal:0.9.0.730"/>
        <cpe-lang:fact-ref name="cpe:/a:free_lan_intra_internet_portal:free_lan_intra_internet_portal:0.9.0.1029"/>
        <cpe-lang:fact-ref name="cpe:/a:free_lan_intra_internet_portal:free_lan_intra_internet_portal:1.0_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:free_lan_intra_internet_portal:free_lan_intra_internet_portal:1.0_rc2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:free_lan_intra_internet_portal:free_lan_intra_internet_portal:0.9.0.730</vuln:product>
      <vuln:product>cpe:/a:free_lan_intra_internet_portal:free_lan_intra_internet_portal:0.9.0.1029</vuln:product>
      <vuln:product>cpe:/a:free_lan_intra_internet_portal:free_lan_intra_internet_portal:1.0_rc1</vuln:product>
      <vuln:product>cpe:/a:free_lan_intra_internet_portal:free_lan_intra_internet_portal:1.0_rc2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0695</vuln:cve-id>
    <vuln:published-datetime>2007-02-03T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:21.077-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=481131&amp;group_id=98260" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=481131&amp;group_id=98260</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-February/001282.html" xml:lang="en">20070203 FLIP SQL injection clarification</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0454" xml:lang="en">ADV-2007-0454</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31902" xml:lang="en">flip-multiple-sql-injection(31902)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in Free LAN In(tra|ter)net Portal (FLIP) before 1.0-RC3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.  NOTE: some sources mention the escape_sqlData, implode_sql, and implode_sqlIn functions, but these are protection schemes, not the vulnerable functions.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0696">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:free_lan_intra_internet_portal:free_lan_intra_internet_portal:0.9.0.730"/>
        <cpe-lang:fact-ref name="cpe:/a:free_lan_intra_internet_portal:free_lan_intra_internet_portal:0.9.0.1029"/>
        <cpe-lang:fact-ref name="cpe:/a:free_lan_intra_internet_portal:free_lan_intra_internet_portal:1.0_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:free_lan_intra_internet_portal:free_lan_intra_internet_portal:1.0_rc2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:free_lan_intra_internet_portal:free_lan_intra_internet_portal:0.9.0.730</vuln:product>
      <vuln:product>cpe:/a:free_lan_intra_internet_portal:free_lan_intra_internet_portal:0.9.0.1029</vuln:product>
      <vuln:product>cpe:/a:free_lan_intra_internet_portal:free_lan_intra_internet_portal:1.0_rc1</vuln:product>
      <vuln:product>cpe:/a:free_lan_intra_internet_portal:free_lan_intra_internet_portal:1.0_rc2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0696</vuln:cve-id>
    <vuln:published-datetime>2007-02-03T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:21.127-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=481131&amp;group_id=98260" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=481131&amp;group_id=98260</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0454" xml:lang="en">ADV-2007-0454</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31900" xml:lang="en">flip-triggererrortext-xss(31900)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in error messages in Free LAN In(tra|ter)net Portal (FLIP) before 1.0-RC3 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, different vectors than CVE-2007-0611.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0697">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mentiss_acgv:acgvannu:1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mentiss_acgv:acgvannu:1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0697</vuln:cve-id>
    <vuln:published-datetime>2007-02-03T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:03.753-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22279" xml:lang="en">22279</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0388" xml:lang="en">ADV-2007-0388</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/31893" xml:lang="en">acgv-modif-security-bypass(31893)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3208" xml:lang="en">3208</vuln:reference>
    </vuln:references>
    <vuln:summary>index2.php in ACGVannu 1.3 and earlier allows remote attackers to change the password or profile of a user via a modified id parameter, related to templates/modif.html.  NOTE: some of these details are obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0698">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mentiss_acgv:acgvannu:1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mentiss_acgv:acgvannu:1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0698</vuln:cve-id>
    <vuln:published-datetime>2007-02-03T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:21.237-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0388" xml:lang="en">ADV-2007-0388</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32257" xml:lang="en">acgv-modif-sql-injection(32257)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in ACGVannu 1.3 and earlier allow remote attackers to execute arbitrary SQL commands via the id_mod parameter to templates/modif.html, and other unspecified vectors.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0699">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:portail_web_php:portail_web_php:0.99"/>
        <cpe-lang:fact-ref name="cpe:/a:portail_web_php:portail_web_php:2.5.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:portail_web_php:portail_web_php:0.99</vuln:product>
      <vuln:product>cpe:/a:portail_web_php:portail_web_php:2.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0699</vuln:cve-id>
    <vuln:published-datetime>2007-02-03T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:51.967-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2223" xml:lang="en">2223</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=480538&amp;group_id=178400" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=480538&amp;group_id=178400</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-February/001269.html" xml:lang="en">20070201 Fwd: php web portail [remote file include &amp; local file include]</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458805/100/0/threaded" xml:lang="en">20070201 php web portail [remote file include &amp; local file include]</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22361" xml:lang="en">22361</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0457" xml:lang="en">ADV-2007-0457</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32121" xml:lang="en">portailwebphp-includes-file-include(32121)</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in includes/includes.php in Guernion Sylvain Portail Web Php (aka Gsylvain35 Portail Web, PwP) before 2.5.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the site_path parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0700">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:portail_web_php:portail_web_php:2.5.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:portail_web_php:portail_web_php:2.5.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0700</vuln:cve-id>
    <vuln:published-datetime>2007-02-03T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:52.497-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-February/001269.html" xml:lang="en">20070201 Fwd: php web portail [remote file include &amp; local file include]</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-February/001280.html" xml:lang="en">20070202 Local File Inclusion inconclusive in PwP (was Fwd: php web portail [remote file include &amp; local fileinclude])</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-February/001281.html" xml:lang="en">20070202 Local File Inclusion inconclusive in PwP (was Fwd: php web portail [remote file include &amp; local fileinclude])</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458805/100/0/threaded" xml:lang="en">20070201 php web portail [remote file include &amp; local file include]</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22361" xml:lang="en">22361</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27962" xml:lang="en">27962</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32115" xml:lang="en">portailwebphp-index-file-include(32115)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/5182" xml:lang="en">5182</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in index.php in Guernion Sylvain Portail Web Php (aka Gsylvain35 Portail Web, PwP) allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.  NOTE: this issue was later reported for 2.5.1.1.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0701">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:epistemon:epistemon:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:epistemon:epistemon:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0701</vuln:cve-id>
    <vuln:published-datetime>2007-02-03T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:03.817-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-February/001266.html" xml:lang="en">20070201 true: Epistemon 1.0 &lt;= Remote File Include Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22360" xml:lang="en">22360</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0459" xml:lang="en">ADV-2007-0459</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3247" xml:lang="en">3247</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in inc/common.inc.php in Epistemon 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc_path parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0702">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpeventman:phpeventman:1.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpeventman:phpeventman:1.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0702</vuln:cve-id>
    <vuln:published-datetime>2007-02-03T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:03.877-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-February/001264.html" xml:lang="en">20070201 true: phpEventMan RFI Vuln.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22358" xml:lang="en">22358</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0460" xml:lang="en">ADV-2007-0460</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3246" xml:lang="en">3246</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple PHP remote file inclusion vulnerabilities in phpEventMan 1.0.2 allow remote attackers to execute arbitrary PHP code via a URL in the level parameter to (1) Shared/controller/text.ctrl.php or (2) UserMan/controller/common.function.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0703">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:webbuilder:webbuilder:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:webbuilder:webbuilder:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0703</vuln:cve-id>
    <vuln:published-datetime>2007-02-03T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:03.940-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-February/001267.html" xml:lang="en">20070201 true: WebBuilder &lt;= 2.0 Remote File Include Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0458" xml:lang="en">ADV-2007-0458</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3249" xml:lang="en">3249</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in library/StageLoader.php in WebBuilder 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[core][module_path] parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0704">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:somery:somery:0.4.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:somery:somery:0.4.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0704</vuln:cve-id>
    <vuln:published-datetime>2007-02-03T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:04.083-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-February/001265.html" xml:lang="en">20070201 True: Somery 0.4.6 (skindir install.php) Remote file include</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/2329" xml:lang="en">2329</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in install.php in Somery 0.4.6 allows remote attackers to execute arbitrary PHP code via a URL in the skindir parameter, a different vector than CVE-2006-4669.  NOTE: the documentation says to remove install.php after installation.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0705">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:fenrir:portable_sleipnir:2.45"/>
        <cpe-lang:fact-ref name="cpe:/a:fenrir:sleipnir:2.49"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:fenrir:portable_sleipnir:2.45</vuln:product>
      <vuln:product>cpe:/a:fenrir:sleipnir:2.49</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0705</vuln:cve-id>
    <vuln:published-datetime>2007-02-03T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:50:34.923-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>JVN</vuln:source>
      <vuln:reference href="http://jvn.jp/jp/JVN%2393700808/index.html" xml:lang="en">JVN#93700808</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.fenrir.co.jp/press/20070126_2.html" xml:lang="en">http://www.fenrir.co.jp/press/20070126_2.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.ipa.go.jp/security/vuln/documents/2006/JVN_93700808.html" xml:lang="en">http://www.ipa.go.jp/security/vuln/documents/2006/JVN_93700808.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0364" xml:lang="en">ADV-2007-0364</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-zone scripting vulnerability in Sleipnir 2.49 and earlier, and Portable Sleipnir 2.45 and earlier, allows remote attackers to bypass Web content zone restrictions via certain script contained in RSS data.  NOTE: some of these details are obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0706">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:fenrir:darksky_rss_bar:1.28_release3::internet_explorer"/>
        <cpe-lang:fact-ref name="cpe:/a:fenrir:darksky_rss_bar:1.28_release3::sleipnir"/>
        <cpe-lang:fact-ref name="cpe:/a:fenrir:darksky_rss_bar:1.28_release3::undonut"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:fenrir:darksky_rss_bar:1.28_release3::internet_explorer</vuln:product>
      <vuln:product>cpe:/a:fenrir:darksky_rss_bar:1.28_release3::sleipnir</vuln:product>
      <vuln:product>cpe:/a:fenrir:darksky_rss_bar:1.28_release3::undonut</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0706</vuln:cve-id>
    <vuln:published-datetime>2007-02-03T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:50:35.033-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>JVN</vuln:source>
      <vuln:reference href="http://jvn.jp/jp/JVN%2393700808/index.html" xml:lang="en">JVN#93700808</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.fenrir.co.jp/press/20070126_2.html" xml:lang="en">http://www.fenrir.co.jp/press/20070126_2.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0365" xml:lang="en">ADV-2007-0365</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-zone scripting vulnerability in Darksky RSS bar for Internet Explorer before 1.29, RSS bar for Sleipnir before 1.29, and RSS bar for unDonut before 1.29 allows remote attackers to bypass Web content zone restrictions via certain script contained in RSS data.  NOTE: some of these details are obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0707">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gom_player:gom_player:2.0.12.3375"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gom_player:gom_player:2.0.12.3375</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0707</vuln:cve-id>
    <vuln:published-datetime>2007-02-03T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:21.407-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.gomplayer.com/forum/viewtopic.html?t=221" xml:lang="en">http://www.gomplayer.com/forum/viewtopic.html?t=221</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32164" xml:lang="en">gomplayer-asx-bo(32164)</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in GOM Player 2.0.12.3375 allows user-assisted remote attackers to execute arbitrary code via a .ASX file with a long URI in the "ref href" tag.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0708">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:comodo:comodo_firewall_pro:2.4.16.174"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:comodo:comodo_firewall_pro:2.4.16.174</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0708</vuln:cve-id>
    <vuln:published-datetime>2007-02-03T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:53.137-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017580" xml:lang="en">1017580</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.matousec.com/info/advisories/Comodo-Multiple-insufficient-argument-validation-of-hooked-SSDT-functions.php" xml:lang="en">http://www.matousec.com/info/advisories/Comodo-Multiple-insufficient-argument-validation-of-hooked-SSDT-functions.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458773/100/0/threaded" xml:lang="en">20070201 Comodo Multiple insufficient argument validation of hooked SSDT function Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22357" xml:lang="en">22357</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32059" xml:lang="en">comodofirewallpro-cmdmon-dos(32059)</vuln:reference>
    </vuln:references>
    <vuln:summary>cmdmon.sys in Comodo Firewall Pro (formerly Comodo Personal Firewall) before 2.4.16.174 does not validate arguments that originate in user mode for the (1) NtConnectPort and (2) NtCreatePort hooked SSDT functions, which allows local users to cause a denial of service (system crash) and possibly gain privileges via invalid arguments.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0709">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:comodo:comodo_firewall_pro:2.4.16.174"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:comodo:comodo_firewall_pro:2.4.16.174</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0709</vuln:cve-id>
    <vuln:published-datetime>2007-02-03T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:53.527-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017580" xml:lang="en">1017580</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.matousec.com/info/advisories/Comodo-Multiple-insufficient-argument-validation-of-hooked-SSDT-functions.php" xml:lang="en">http://www.matousec.com/info/advisories/Comodo-Multiple-insufficient-argument-validation-of-hooked-SSDT-functions.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458773/100/0/threaded" xml:lang="en">20070201 Comodo Multiple insufficient argument validation of hooked SSDT function Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22357" xml:lang="en">22357</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32059" xml:lang="en">comodofirewallpro-cmdmon-dos(32059)</vuln:reference>
    </vuln:references>
    <vuln:summary>cmdmon.sys in Comodo Firewall Pro (formerly Comodo Personal Firewall) 2.4.16.174 and earlier does not validate arguments that originate in user mode for the (1) NtCreateSection, (2) NtOpenProcess, (3) NtOpenSection, (4) NtOpenThread, and (5) NtSetValueKey hooked SSDT functions, which allows local users to cause a denial of service (system crash) and possibly gain privileges via invalid arguments.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0710">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:apple:ichat"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:ichat</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0710</vuln:cve-id>
    <vuln:published-datetime>2007-02-16T14:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:18:36.677-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-02-20T11:37:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305102" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305102</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Feb/msg00000.html" xml:lang="en">APPLE-SA-2007-02-15</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/836024" xml:lang="en">VU#836024</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22304" xml:lang="en">22304</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017661" xml:lang="en">1017661</vuln:reference>
    </vuln:references>
    <vuln:summary>The Bonjour functionality in iChat in Apple Mac OS X 10.3.9 allows remote attackers to cause a denial of service (persistent application crash) via unspecified vectors, possibly related to CVE-2007-0614.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0711">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:4.1.2:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:5.0.1:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:5.0.2:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.0.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.0.1:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.0.2:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.1.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.1.1:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.2.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.3.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.4.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.5.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.5.1:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.5.2:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.1:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.2:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.3:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.4:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.1:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.2:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.3:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.4:-:windows"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:quicktime:3.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:4.1.2:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:5.0.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:5.0.2:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.0.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.0.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.0.2:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.1.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.1.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.2.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.3.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.4.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.5.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.5.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.5.2:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.2:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.3:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.4:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.2:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.3:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.4:-:windows</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0711</vuln:cve-id>
    <vuln:published-datetime>2007-03-05T17:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:17.370-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305149" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305149</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html" xml:lang="en">APPLE-SA-2007-03-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/568689" xml:lang="en">VU#568689</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22827" xml:lang="en">22827</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017725" xml:lang="en">1017725</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-065A.html" xml:lang="en">TA07-065A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0825" xml:lang="en">ADV-2007-0825</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32814" xml:lang="en">quicktime-3gpvideo-overflow(32814)</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in Apple QuickTime before 7.1.5, when installed on Windows operating systems, allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted 3GP video file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0712">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:4.1.2:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:5.0.1:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:5.0.2:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.0.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.0.1:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.0.2:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.1.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.1.1:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.2.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.3.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.4.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.5.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.5.1:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.5.2:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.1:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.2:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.3:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.4:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.1:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.2:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.3:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.4:-:windows"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:4.1.2:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:5.0.1:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:5.0.2:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.0.0:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.0.1:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.0.2:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.1.0:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.1.1:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.2.0:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.3.0:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.4.0:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.5.0:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.5.1:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.5.2:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.0:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.1:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.2:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.3:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.4:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.0:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.1:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.2:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.3:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.4:-:mac"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.0"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.1"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.2"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.3"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.4"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.5"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.7"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.9"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.10"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.11"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.0"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.1"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.2"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.3"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.4"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.5"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.6"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:quicktime:3.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:4.1.2:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:4.1.2:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:5.0.1:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:5.0.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:5.0.2:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:5.0.2:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.0.0:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.0.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.0.1:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.0.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.0.2:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.0.2:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.1.0:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.1.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.1.1:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.1.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.2.0:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.2.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.3.0:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.3.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.4.0:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.4.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.5.0:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.5.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.5.1:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.5.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.5.2:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.5.2:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.0:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.1:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.2:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.2:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.3:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.3:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.4:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.4:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.0:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.1:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.2:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.2:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.3:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.3:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.4:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.4:-:windows</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0712</vuln:cve-id>
    <vuln:published-datetime>2007-03-05T17:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:17.370-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305149" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305149</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html" xml:lang="en">APPLE-SA-2007-03-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/822481" xml:lang="en">VU#822481</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22827" xml:lang="en">22827</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017725" xml:lang="en">1017725</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-065A.html" xml:lang="en">TA07-065A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0825" xml:lang="en">ADV-2007-0825</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32816" xml:lang="en">quicktime-midi-files-bo(32816)</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MIDI file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0713">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:quicktime:7.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.3</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0713</vuln:cve-id>
    <vuln:published-datetime>2007-03-05T17:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:53.887-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305149" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305149</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html" xml:lang="en">APPLE-SA-2007-03-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/880561" xml:lang="en">VU#880561</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.piotrbania.com/all/adv/quicktime-heap-adv-7.1.txt" xml:lang="en">http://www.piotrbania.com/all/adv/quicktime-heap-adv-7.1.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461983/100/0/threaded" xml:lang="en">20070306 Apple QuickTime Player Remote Heap Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22827" xml:lang="en">22827</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22843" xml:lang="en">22843</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017725" xml:lang="en">1017725</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-065A.html" xml:lang="en">TA07-065A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0825" xml:lang="en">ADV-2007-0825</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32817" xml:lang="en">quicktime-quicktime-bo(32817)</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted QuickTime movie file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0714">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:4.1.2:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:5.0.1:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:5.0.2:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.0.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.0.1:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.0.2:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.1.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.1.1:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.2.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.3.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.4.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.5.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.5.1:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.5.2:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.1:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.2:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.3:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.4:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.0:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.1:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.2:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.3:-:windows"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.4:-:windows"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:3.0"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:4.1.2:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:5.0.1:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:5.0.2:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.0.0:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.0.1:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.0.2:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.1.0:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.1.1:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.2.0:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.3.0:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.4.0:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.5.0:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.5.1:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:6.5.2:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.0:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.1:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.2:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.3:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.4:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.0:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.1:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.2:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.3:-:mac"/>
          <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.4:-:mac"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.0"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.1"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.2"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.3"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.4"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.5"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.7"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.9"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.10"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.11"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.0"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.1"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.2"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.3"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.4"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.5"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.5.6"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:quicktime:3.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:4.1.2:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:4.1.2:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:5.0.1:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:5.0.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:5.0.2:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:5.0.2:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.0.0:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.0.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.0.1:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.0.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.0.2:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.0.2:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.1.0:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.1.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.1.1:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.1.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.2.0:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.2.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.3.0:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.3.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.4.0:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.4.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.5.0:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.5.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.5.1:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.5.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.5.2:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:6.5.2:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.0:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.1:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.2:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.2:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.3:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.3:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.4:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.4:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.0:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.0:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.1:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.1:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.2:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.2:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.3:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.3:-:windows</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.4:-:mac</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.4:-:windows</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0714</vuln:cve-id>
    <vuln:published-datetime>2007-03-05T17:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:17.370-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-03/0003.html" xml:lang="en">20070306 Apple QuickTime udta ATOM Integer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305149" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305149</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html" xml:lang="en">APPLE-SA-2007-03-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://secway.org/advisory/AD20070306.txt" xml:lang="en">http://secway.org/advisory/AD20070306.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/861817" xml:lang="en">VU#861817</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461999/100/0/threaded" xml:lang="en">20070306 Apple QuickTime udta ATOM Integer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/462153/100/0/threaded" xml:lang="en">20070307 ZDI-07-010: Apple Quicktime UDTA Parsing Heap Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22827" xml:lang="en">22827</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22844" xml:lang="en">22844</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017725" xml:lang="en">1017725</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-065A.html" xml:lang="en">TA07-065A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0825" xml:lang="en">ADV-2007-0825</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-07-010.html" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-07-010.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32819" xml:lang="en">quicktime-udta-atoms-overflow(32819)</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted QuickTime movie with a User Data Atom (UDTA) with an Atom size field with a large value.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0715">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:quicktime:7.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.3</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0715</vuln:cve-id>
    <vuln:published-datetime>2007-03-05T17:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:21.843-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305149" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305149</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html" xml:lang="en">APPLE-SA-2007-03-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/448745" xml:lang="en">VU#448745</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22827" xml:lang="en">22827</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017725" xml:lang="en">1017725</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-065A.html" xml:lang="en">TA07-065A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0825" xml:lang="en">ADV-2007-0825</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32821" xml:lang="en">quicktime-pict-file-bo(32821)</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PICT file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0716">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:quicktime:7.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.3</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0716</vuln:cve-id>
    <vuln:published-datetime>2007-03-05T17:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:21.907-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305149" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305149</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html" xml:lang="en">APPLE-SA-2007-03-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/642433" xml:lang="en">VU#642433</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22827" xml:lang="en">22827</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017725" xml:lang="en">1017725</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-065A.html" xml:lang="en">TA07-065A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0825" xml:lang="en">ADV-2007-0825</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32822" xml:lang="en">quicktime-qtif-bo(32822)</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted QTIF file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0717">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:quicktime:7.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.3</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0717</vuln:cve-id>
    <vuln:published-datetime>2007-03-05T17:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:21.970-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305149" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305149</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html" xml:lang="en">APPLE-SA-2007-03-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/410993" xml:lang="en">VU#410993</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22827" xml:lang="en">22827</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017725" xml:lang="en">1017725</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-065A.html" xml:lang="en">TA07-065A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0825" xml:lang="en">ADV-2007-0825</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32823" xml:lang="en">quicktime-qtif-overflow(32823)</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted QTIF file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0718">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:quicktime:7.0</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.3</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.0.4</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.1</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.3</vuln:product>
      <vuln:product>cpe:/a:apple:quicktime:7.1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0718</vuln:cve-id>
    <vuln:published-datetime>2007-03-05T17:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:56.577-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305149" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305149</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=486" xml:lang="en">20070305 Apple QuickTime Color Table ID Heap Corruption Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html" xml:lang="en">APPLE-SA-2007-03-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/313225" xml:lang="en">VU#313225</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/462012/100/0/threaded" xml:lang="en">20070306 [Reversemode Advisory] Apple Quicktime Color ID remote heap corruption</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22827" xml:lang="en">22827</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22839" xml:lang="en">22839</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017725" xml:lang="en">1017725</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-065A.html" xml:lang="en">TA07-065A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0825" xml:lang="en">ADV-2007-0825</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32826" xml:lang="en">quicktime-qtif-file-bo(32826)</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a QTIF file with a Video Sample Description containing a Color table ID of 0, which triggers memory corruption when QuickTime assumes that a color table exists.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0719">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0719</vuln:cve-id>
    <vuln:published-datetime>2007-03-13T17:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:50:36.453-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305214" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" xml:lang="en">APPLE-SA-2007-03-13</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/449440" xml:lang="en">VU#449440</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22948" xml:lang="en">22948</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017751" xml:lang="en">1017751</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" xml:lang="en">TA07-072A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0930" xml:lang="en">ADV-2007-0930</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to execute arbitrary code via an image with a crafted ColorSync profile.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0720">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cups:cups"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cups:cups</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0720</vuln:cve-id>
    <vuln:published-datetime>2007-03-13T17:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:33:57.747-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11046" name="oval:org.mitre.oval:def:11046"/>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305214" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2785" xml:lang="en">FEDORA-2007-1219</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" xml:lang="en">APPLE-SA-2007-03-13</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200703-28.xml" xml:lang="en">GLSA-200703-28</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2007-194.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2007-194.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:086" xml:lang="en">MDKSA-2007:086</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_14_sr.html" xml:lang="en">SUSE-SR:2007:014</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_9_sr.html" xml:lang="en">SUSE-SR:2007:009</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0123.html" xml:lang="en">RHSA-2007:0123</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/463846/100/0/threaded" xml:lang="en">20070325 FLEA-2007-0003-1: cups</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22948" xml:lang="en">22948</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23127" xml:lang="en">23127</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017750" xml:lang="en">1017750</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" xml:lang="en">TA07-072A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0930" xml:lang="en">ADV-2007-0930</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0949" xml:lang="en">ADV-2007-0949</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=232243" xml:lang="en">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=232243</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1173" xml:lang="en">https://issues.rpath.com/browse/RPL-1173</vuln:reference>
    </vuln:references>
    <vuln:summary>The CUPS service on multiple platforms allows remote attackers to cause a denial of service (service hang) via a "partially-negotiated" SSL connection, which prevents other requests from being accepted.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0721">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0721</vuln:cve-id>
    <vuln:published-datetime>2007-03-13T18:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:50:36.750-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305214" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" xml:lang="en">APPLE-SA-2007-03-13</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22948" xml:lang="en">22948</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017751" xml:lang="en">1017751</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" xml:lang="en">TA07-072A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0930" xml:lang="en">ADV-2007-0930</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in diskimages-helper in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to execute arbitrary code via a crafted compressed disk image that triggers memory corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0722">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0722</vuln:cve-id>
    <vuln:published-datetime>2007-03-13T18:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:50:36.847-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305214" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" xml:lang="en">APPLE-SA-2007-03-13</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/124280" xml:lang="en">VU#124280</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22948" xml:lang="en">22948</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017751" xml:lang="en">1017751</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" xml:lang="en">TA07-072A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0930" xml:lang="en">ADV-2007-0930</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to execute arbitrary code via a crafted AppleSingleEncoding disk image.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0723">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0723</vuln:cve-id>
    <vuln:published-datetime>2007-03-13T18:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:50:36.970-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>8.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305214" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" xml:lang="en">APPLE-SA-2007-03-13</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/557064" xml:lang="en">VU#557064</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22948" xml:lang="en">22948</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017751" xml:lang="en">1017751</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" xml:lang="en">TA07-072A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0930" xml:lang="en">ADV-2007-0930</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the authentication feature for DirectoryService (DS Plug-Ins) for Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote authenticated LDAP users to modify the root password and gain privileges via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0724">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0724</vuln:cve-id>
    <vuln:published-datetime>2007-03-13T18:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:22.093-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305214" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305391" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305391</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" xml:lang="en">APPLE-SA-2007-04-19</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" xml:lang="en">APPLE-SA-2007-03-13</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22948" xml:lang="en">22948</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017751" xml:lang="en">1017751</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017942" xml:lang="en">1017942</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" xml:lang="en">TA07-072A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" xml:lang="en">TA07-109A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0930" xml:lang="en">ADV-2007-0930</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1470" xml:lang="en">ADV-2007-1470</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32973" xml:lang="en">macos-hid-privilege-escalation(32973)</vuln:reference>
    </vuln:references>
    <vuln:summary>The IOKit HID interface in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 does not sufficiently limit access to certain controls, which allows local users to gain privileges by using HID device events to read keystrokes from the console.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0725">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0725</vuln:cve-id>
    <vuln:published-datetime>2007-04-24T12:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:50:37.203-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305391" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305391</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" xml:lang="en">APPLE-SA-2007-04-19</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23569" xml:lang="en">23569</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" xml:lang="en">TA07-109A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1470" xml:lang="en">ADV-2007-1470</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the AirPortDriver module for AirPort in Apple Mac OS X 10.3.9 through 10.4.9, when running on hardware with the original AirPort wireless card, allows local users to execute arbitrary code by "sending malformed control commands."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0726">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0726</vuln:cve-id>
    <vuln:published-datetime>2007-03-13T18:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:22.157-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305214" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" xml:lang="en">APPLE-SA-2007-03-13</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22948" xml:lang="en">22948</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017756" xml:lang="en">1017756</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" xml:lang="en">TA07-072A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0930" xml:lang="en">ADV-2007-0930</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32975" xml:lang="en">macos-openssh-dos(32975)</vuln:reference>
    </vuln:references>
    <vuln:summary>The SSH key generation process in OpenSSH in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote attackers to cause a denial of service by connecting to the server before SSH has finished creating keys, which causes the keys to be regenerated and can break trust relationships that were based on the original keys.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0727">
    <vuln:cve-id>CVE-2007-0727</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:05.573-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:05.590-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2007. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0728">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0728</vuln:cve-id>
    <vuln:published-datetime>2007-03-13T18:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:22.237-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.4</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305214" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" xml:lang="en">APPLE-SA-2007-03-13</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22948" xml:lang="en">22948</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017751" xml:lang="en">1017751</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" xml:lang="en">TA07-072A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0930" xml:lang="en">ADV-2007-0930</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32976" xml:lang="en">macos-usbprinter-file-overwrite(32976)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 creates files insecurely while initializing a USB printer, which allows local users to create or overwrite arbitrary files.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0729">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_preview.app:3.0.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.0"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.0.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.1.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_preview.app:3.0.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.0</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.1.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.2.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0729</vuln:cve-id>
    <vuln:published-datetime>2007-04-24T12:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:50:37.533-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305391" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305391</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" xml:lang="en">APPLE-SA-2007-04-19</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/312424" xml:lang="en">VU#312424</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23569" xml:lang="en">23569</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017944" xml:lang="en">1017944</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" xml:lang="en">TA07-109A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1470" xml:lang="en">ADV-2007-1470</vuln:reference>
    </vuln:references>
    <vuln:summary>Apple File Protocol (AFP) Client in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment before executing commands, which allows local users to gain privileges by setting unspecified environment variables.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0730">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.1"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.2"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.3"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.4"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.5"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.7"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:apple:server_manager"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:server_manager</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0730</vuln:cve-id>
    <vuln:published-datetime>2007-03-13T18:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:22.297-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305214" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" xml:lang="en">APPLE-SA-2007-03-13</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22948" xml:lang="en">22948</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017751" xml:lang="en">1017751</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" xml:lang="en">TA07-072A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0930" xml:lang="en">ADV-2007-0930</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32978" xml:lang="en">macos-servermanager-authentication-bypass(32978)</vuln:reference>
    </vuln:references>
    <vuln:summary>Server Manager (servermgrd) in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 does not sufficiently validate authentication credentials, which allows remote attackers to bypass authentication and modify system configuration.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0731">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0731</vuln:cve-id>
    <vuln:published-datetime>2007-03-13T18:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:22.343-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305214" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" xml:lang="en">APPLE-SA-2007-03-13</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22948" xml:lang="en">22948</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017754" xml:lang="en">1017754</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" xml:lang="en">TA07-072A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0930" xml:lang="en">ADV-2007-0930</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32979" xml:lang="en">macos-smbfileserver-bo(32979)</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in the Apple-specific Samba module (SMB File Server) in Apple Mac OS X 10.4 through 10.4.8 allows context-dependent attackers to execute arbitrary code via a long ACL.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0732">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0732</vuln:cve-id>
    <vuln:published-datetime>2007-04-24T12:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:50:37.877-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305391" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305391</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" xml:lang="en">APPLE-SA-2007-04-19</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23569" xml:lang="en">23569</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017942" xml:lang="en">1017942</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" xml:lang="en">TA07-109A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1470" xml:lang="en">ADV-2007-1470</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the CoreServices daemon in CarbonCore in Apple Mac OS X 10.4 through 10.4.9 allows local users to gain privileges via unspecified vectors involving "obtaining a send right to [the] Mach task port."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0733">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.1"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.2"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.3"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.4"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.5"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.7"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:apple:imageio"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:imageio</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0733</vuln:cve-id>
    <vuln:published-datetime>2007-03-13T18:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:22.407-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305214" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" xml:lang="en">APPLE-SA-2007-03-13</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/873868" xml:lang="en">VU#873868</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22948" xml:lang="en">22948</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017758" xml:lang="en">1017758</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" xml:lang="en">TA07-072A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0930" xml:lang="en">ADV-2007-0930</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32974" xml:lang="en">macos-imageio-code-execution(32974)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in ImageIO in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted RAW image that triggers memory corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0734">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/h:apple:airport_extreme:7.0"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.1"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.2"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.3"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.4"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.5"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.7"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.9"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0734</vuln:cve-id>
    <vuln:published-datetime>2007-04-10T18:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:22.470-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.4</cvss:score>
        <cvss:access-vector>ADJACENT_NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305366" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305366</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305391" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305391</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2007/Apr/msg00000.html" xml:lang="en">APPLE-SA-2007-04-09</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" xml:lang="en">APPLE-SA-2007-04-19</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23396" xml:lang="en">23396</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23569" xml:lang="en">23569</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017889" xml:lang="en">1017889</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017942" xml:lang="en">1017942</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" xml:lang="en">TA07-109A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1308" xml:lang="en">ADV-2007-1308</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1470" xml:lang="en">ADV-2007-1470</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33527" xml:lang="en">airportextreme-airportdisk-info-disclosure(33527)</vuln:reference>
    </vuln:references>
    <vuln:summary>fsck, as used by the AirPort Disk feature of the AirPort Extreme Base Station with 802.11n before Firmware Update 7.1, and by Apple Mac OS X 10.3.9 through 10.4.9, does not properly enforce password protection of a USB hard drive, which allows context-dependent attackers to list arbitrary directories or execute arbitrary code, resulting from memory corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0735">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0735</vuln:cve-id>
    <vuln:published-datetime>2007-04-24T13:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:50:38.220-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305391" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305391</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" xml:lang="en">APPLE-SA-2007-04-19</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23569" xml:lang="en">23569</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017942" xml:lang="en">1017942</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" xml:lang="en">TA07-109A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1470" xml:lang="en">ADV-2007-1470</vuln:reference>
    </vuln:references>
    <vuln:summary>Use-after-free vulnerability in Libinfo in Apple Mac OS X 10.3.9 through 10.4.9 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors involving crafted web pages that trigger certain error conditions that are not properly reported in certain circumstances, resulting in accessing deallocated memory.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0736">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0736</vuln:cve-id>
    <vuln:published-datetime>2007-04-24T13:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:22.530-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305391" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305391</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" xml:lang="en">APPLE-SA-2007-04-19</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23569" xml:lang="en">23569</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017942" xml:lang="en">1017942</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" xml:lang="en">TA07-109A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1470" xml:lang="en">ADV-2007-1470</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33782" xml:lang="en">macos-rpc-code-execution(33782)</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in the RPC library in Libinfo in Apple Mac OS X 10.3.9 through 10.4.9 allows remote attackers to execute arbitrary code via crafted requests to portmap.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0737">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0737</vuln:cve-id>
    <vuln:published-datetime>2007-04-24T13:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:50:38.423-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305391" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305391</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" xml:lang="en">APPLE-SA-2007-04-19</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23569" xml:lang="en">23569</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017939" xml:lang="en">1017939</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" xml:lang="en">TA07-109A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1470" xml:lang="en">ADV-2007-1470</vuln:reference>
    </vuln:references>
    <vuln:summary>The Login Window in Apple Mac OS X 10.3.9 through 10.4.9 does not properly check certain environment variables, which allows local users to gain privileges via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0738">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0738</vuln:cve-id>
    <vuln:published-datetime>2007-04-24T13:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:50:38.547-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305391" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305391</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" xml:lang="en">APPLE-SA-2007-04-19</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23569" xml:lang="en">23569</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017939" xml:lang="en">1017939</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" xml:lang="en">TA07-109A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1470" xml:lang="en">ADV-2007-1470</vuln:reference>
    </vuln:references>
    <vuln:summary>The Login Window in Apple Mac OS X 10.4 through 10.4.9 does not display the screen saver authentication dialog in certain circumstances when waking from sleep, even though the "require a password to wake the computer from sleep" option is enabled, which allows local users to bypass authentication controls.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0739">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0739</vuln:cve-id>
    <vuln:published-datetime>2007-04-24T13:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:50:38.657-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305391" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305391</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" xml:lang="en">APPLE-SA-2007-04-19</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23569" xml:lang="en">23569</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017939" xml:lang="en">1017939</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" xml:lang="en">TA07-109A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1470" xml:lang="en">ADV-2007-1470</vuln:reference>
    </vuln:references>
    <vuln:summary>The Login Window in Apple Mac OS X 10.4 through 10.4.9 displays the software update window beneath the loginwindow authentication dialog in certain circumstances related to running scheduled tasks, which allows local users to bypass authentication controls.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0740">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0740</vuln:cve-id>
    <vuln:published-datetime>2007-05-24T18:30:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:22.593-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305530" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305530</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2007/May/msg00004.html" xml:lang="en">APPLE-SA-2007-05-24</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/24144" xml:lang="en">24144</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018121" xml:lang="en">1018121</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1939" xml:lang="en">ADV-2007-1939</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/34498" xml:lang="en">macos-diskimage-code-execution(34498)</vuln:reference>
    </vuln:references>
    <vuln:summary>Alias Manager in Apple Mac OS X 10.3.9 and 10.4.9 does not display files with the same name in mounted disk images that have the same name, which might allow user-assisted attackers to trick a user into executing malicious files.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0741">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0741</vuln:cve-id>
    <vuln:published-datetime>2007-04-24T13:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:50:38.860-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305391" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305391</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" xml:lang="en">APPLE-SA-2007-04-19</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23569" xml:lang="en">23569</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017942" xml:lang="en">1017942</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" xml:lang="en">TA07-109A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1470" xml:lang="en">ADV-2007-1470</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in natd in network_cmds in Apple Mac OS X 10.3.9 through 10.4.9, when Internet Sharing is enabled, allows remote attackers to execute arbitrary code via malformed RTSP packets.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0742">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0742</vuln:cve-id>
    <vuln:published-datetime>2007-04-24T13:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:50:38.970-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305391" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305391</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" xml:lang="en">APPLE-SA-2007-04-19</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23569" xml:lang="en">23569</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017942" xml:lang="en">1017942</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" xml:lang="en">TA07-109A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1470" xml:lang="en">ADV-2007-1470</vuln:reference>
    </vuln:references>
    <vuln:summary>The WebFoundation framework in Apple Mac OS X 10.3.9 and earlier allows subdomain cookies to be accessed by the parent domain, which allows remote attackers to obtain sensitive information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0743">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0743</vuln:cve-id>
    <vuln:published-datetime>2007-04-24T13:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:50:39.097-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305391" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305391</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" xml:lang="en">APPLE-SA-2007-04-19</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23569" xml:lang="en">23569</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017942" xml:lang="en">1017942</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" xml:lang="en">TA07-109A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1470" xml:lang="en">ADV-2007-1470</vuln:reference>
    </vuln:references>
    <vuln:summary>URLMount in Apple Mac OS X 10.3.9 through 10.4.9 passes the username and password credentials for mounting filesystems on SMB servers as command line arguments to the mount_sub command, which may allow local users to obtain sensitive information by listing the process.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0744">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0744</vuln:cve-id>
    <vuln:published-datetime>2007-04-24T13:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:50:39.187-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305391" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305391</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" xml:lang="en">APPLE-SA-2007-04-19</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23569" xml:lang="en">23569</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" xml:lang="en">TA07-109A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1470" xml:lang="en">ADV-2007-1470</vuln:reference>
    </vuln:references>
    <vuln:summary>SMB in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment when executing commands, which allows local users to gain privileges by setting unspecified environment variables.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0745">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0745</vuln:cve-id>
    <vuln:published-datetime>2007-05-02T17:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:22.640-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.1</cvss:score>
        <cvss:access-vector>ADJACENT_NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2007/May/msg00000.html" xml:lang="en">APPLE-SA-2007-05-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017990" xml:lang="en">1017990</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/34001" xml:lang="en">macos-ftpserver-unauthorized-access(34001)</vuln:reference>
    </vuln:references>
    <vuln:summary>The Apple Security Update 2007-004 uses an incorrect configuration file for FTPServer in Apple Mac OS X Server 10.4.9, which might allow remote authenticated users to access additional directories.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0746">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0746</vuln:cve-id>
    <vuln:published-datetime>2007-04-24T13:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:50:39.377-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305391" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305391</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" xml:lang="en">APPLE-SA-2007-04-19</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/969969" xml:lang="en">VU#969969</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23569" xml:lang="en">23569</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017942" xml:lang="en">1017942</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" xml:lang="en">TA07-109A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1470" xml:lang="en">ADV-2007-1470</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in the VideoConference framework in Apple Mac OS X 10.3.9 through 10.4.9 allows remote attackers to execute arbitrary code via a "crafted SIP packet when initializing an audio/video conference".</vuln:summary>
  </entry>
  <entry id="CVE-2007-0747">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0747</vuln:cve-id>
    <vuln:published-datetime>2007-04-24T13:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-07-03T11:33:14.137-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305391" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305391</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" xml:lang="en">APPLE-SA-2007-04-19</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/474969" xml:lang="en">VU#474969</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23569" xml:lang="en">23569</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017942" xml:lang="en">1017942</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" xml:lang="en">TA07-109A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1470" xml:lang="en">ADV-2007-1470</vuln:reference>
    </vuln:references>
    <vuln:summary>load_webdav in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment when mounting a WebDAV filesystem, which allows local users to gain privileges by setting unspecified environment variables.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0748">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:darwin_streaming_server:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:darwin_streaming_server:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:darwin_streaming_server:5.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.8"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.1"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:apple:darwin_streaming_server:4.1.3"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:darwin_streaming_server:4.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:darwin_streaming_server:4.1.3</vuln:product>
      <vuln:product>cpe:/a:apple:darwin_streaming_server:5.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:darwin_streaming_server:5.5.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0748</vuln:cve-id>
    <vuln:published-datetime>2007-05-13T18:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:22.737-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305495" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305495</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=533" xml:lang="en">20070510 Apple Darwin Streaming Proxy Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/May/msg00002.html" xml:lang="en">APPLE-SA-2007-05-10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23918" xml:lang="en">23918</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018047" xml:lang="en">1018047</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1770" xml:lang="en">ADV-2007-1770</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/34225" xml:lang="en">darwin-trackid-bo(34225)</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in Apple Darwin Streaming Proxy, when using Darwin Streaming Server before 5.5.5, allows remote attackers to execute arbitrary code via multiple trackID values in a SETUP RTSP request.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0749">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:darwin_streaming_server:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:darwin_streaming_server:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apple:darwin_streaming_server:5.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.2.8"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.1"/>
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:apple:darwin_streaming_server:4.1.3"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:darwin_streaming_server:4.1.2</vuln:product>
      <vuln:product>cpe:/a:apple:darwin_streaming_server:4.1.3</vuln:product>
      <vuln:product>cpe:/a:apple:darwin_streaming_server:5.0.1</vuln:product>
      <vuln:product>cpe:/a:apple:darwin_streaming_server:5.5.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0749</vuln:cve-id>
    <vuln:published-datetime>2007-05-13T18:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:22.797-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305495" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305495</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=533" xml:lang="en">20070510 Apple Darwin Streaming Proxy Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/May/msg00002.html" xml:lang="en">APPLE-SA-2007-05-10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23918" xml:lang="en">23918</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018047" xml:lang="en">1018047</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1770" xml:lang="en">ADV-2007-1770</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/34222" xml:lang="en">darwin-iscommand-bo(34222)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple stack-based buffer overflows in the is_command function in proxy.c in Apple Darwin Streaming Proxy, when using Darwin Streaming Server before 5.5.5, allow remote attackers to execute arbitrary code via a long (1) cmd or (2) server value in an RTSP request.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0750">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0750</vuln:cve-id>
    <vuln:published-datetime>2007-05-24T18:30:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:22.860-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305530" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305530</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2007/May/msg00004.html" xml:lang="en">APPLE-SA-2007-05-24</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/24144" xml:lang="en">24144</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018114" xml:lang="en">1018114</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1939" xml:lang="en">ADV-2007-1939</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/34499" xml:lang="en">macos-pdf-bo(34499)</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in CoreGraphics in Apple Mac OS X 10.4 up to 10.4.9 allows remote user-assisted attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted PDF file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0751">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0751</vuln:cve-id>
    <vuln:published-datetime>2007-05-24T18:30:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:22.923-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305530" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305530</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2007/May/msg00004.html" xml:lang="en">APPLE-SA-2007-05-24</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/24144" xml:lang="en">24144</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018117" xml:lang="en">1018117</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1939" xml:lang="en">ADV-2007-1939</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/34500" xml:lang="en">macos-tmpfilesystem-dos(34500)</vuln:reference>
    </vuln:references>
    <vuln:summary>A cleanup script in crontabs in Apple Mac OS X 10.3.9 and 10.4.9 might delete filesystems that have been mounted in /tmp, which might allow local users to cause a denial of service, related to the find command.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0752">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0752</vuln:cve-id>
    <vuln:published-datetime>2007-05-24T18:30:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:23.203-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305530" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305530</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=537" xml:lang="en">20070524 Apple Computer Mac OS X pppd Plugin Loading Privilege Escalation Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2007/May/msg00004.html" xml:lang="en">APPLE-SA-2007-05-24</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/24144" xml:lang="en">24144</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018124" xml:lang="en">1018124</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1939" xml:lang="en">ADV-2007-1939</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/34503" xml:lang="en">macos-pppd-privilege-escalation(34503)</vuln:reference>
    </vuln:references>
    <vuln:summary>The PPP daemon (pppd) in Apple Mac OS X 10.4.8 checks ownership of the stdin file descriptor to determine if the invoker has sufficient privileges, which allows local users to load arbitrary plugins and gain root privileges by bypassing this check.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0753">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.6"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.7"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.3.9</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.1</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.2</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.3</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.4</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.5</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.6</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.7</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0753</vuln:cve-id>
    <vuln:published-datetime>2007-05-24T18:30:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:04.090-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-134"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305530" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305530</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2007/May/msg00004.html" xml:lang="en">APPLE-SA-2007-05-24</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/469882/100/0/threaded" xml:lang="en">20070529 Mac OS X vpnd local format string</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/469889/100/0/threaded" xml:lang="en">20070529 Re: Mac OS X vpnd local format string</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/24144" xml:lang="en">24144</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/24208" xml:lang="en">24208</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018125" xml:lang="en">1018125</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1939" xml:lang="en">ADV-2007-1939</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/34505" xml:lang="en">macos-vpnd-format-string(34505)</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in the VPN daemon (vpnd) in Apple Mac OS X 10.3.9 and 10.4.9 allows local users to execute arbitrary code via the -i parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0754">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:quicktime:7.1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:quicktime:7.1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0754</vuln:cve-id>
    <vuln:published-datetime>2007-05-14T17:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:04.777-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=304357" xml:lang="en">http://docs.info.apple.com/article.html?artnum=304357</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://dvlabs.tippingpoint.com/advisory/TPTI-07-07" xml:lang="en">http://dvlabs.tippingpoint.com/advisory/TPTI-07-07</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2703" xml:lang="en">2703</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/468305/100/0/threaded" xml:lang="en">20070511 TPTI-07-07: Apple QuickTime STSD Parsing Heap Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23923" xml:lang="en">23923</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/34244" xml:lang="en">quicktime-stsd-bo(34244)</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted Sample Table Sample Descriptor (STSD) atom size in a QuickTime movie.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0756">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:chicken_of_the_vnc:chicken_of_the_vnc:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:chicken_of_the_vnc:chicken_of_the_vnc:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0756</vuln:cve-id>
    <vuln:published-datetime>2007-02-05T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:05.230-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2220" xml:lang="en">2220</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458907/100/0/threaded" xml:lang="en">20070202 Chicken of the VNC 2.0 remote DoS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/466966/100/0/threaded" xml:lang="en">20070426 Re: Chicken of the VNC 2.0 remote DoS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22372" xml:lang="en">22372</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32166" xml:lang="en">cotv-serverinit-dos(32166)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3257" xml:lang="en">3257</vuln:reference>
    </vuln:references>
    <vuln:summary>Chicken of the VNC (cotv) 2.0 allows remote attackers to cause a denial of service (application crash) via a large computer-name size value in a ServerInit packet, which triggers a failed malloc and a resulting NULL dereference.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0757">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:miguel_nunes:call_of_duty_2_dreamstats_system:4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:miguel_nunes:call_of_duty_2_dreamstats_system:4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0757</vuln:cve-id>
    <vuln:published-datetime>2007-02-05T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:04.207-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-February/001272.html" xml:lang="en">20070202 true: DreamStats V 4.2=(index.php)=>Remote File Include</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22371" xml:lang="en">22371</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0479" xml:lang="en">ADV-2007-0479</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32160" xml:lang="en">cod2dreamstats-index-file-include(32160)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3251" xml:lang="en">3251</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in index.php in Miguel Nunes Call of Duty 2 (CoD2) DreamStats System 4.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the rootpath parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0758">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpprobid:phpprobid:5.24"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpprobid:phpprobid:5.24</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0758</vuln:cve-id>
    <vuln:published-datetime>2007-02-05T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:23.530-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22374" xml:lang="en">22374</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32273" xml:lang="en">phpprobid-lang-file-include(32273)</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in lang.php in PHPProbid 5.24 allows remote attackers to execute arbitrary PHP code via a URL in the SRC attribute of an HTML element in the lang parameter.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0759">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:umberto_caldera:easymoblog:0.5.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:umberto_caldera:easymoblog:0.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0759</vuln:cve-id>
    <vuln:published-datetime>2007-02-05T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:41:45.827-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0052.html" xml:lang="en">20070201 Remote Sql Injection in EasyMoblog 0.5.1 # 2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0054.html" xml:lang="en">20070201 Remote Sql Injection in EasyMoblog 0.5.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22369" xml:lang="en">22369</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zion-security.com/text/Sql_Vulnerability_EasymoBlog%232.txt" xml:lang="en">http://www.zion-security.com/text/Sql_Vulnerability_EasymoBlog%232.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zion-security.com/text/Sql_Vulnerability_EasymoBlog.txt" xml:lang="en">http://www.zion-security.com/text/Sql_Vulnerability_EasymoBlog.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in EasyMoblog 0.5.1 allow remote attackers to execute arbitrary SQL commands via the (1) i or (2) post_id parameter to add_comment.php, which triggers an injection in libraries.inc.php; or (3) the i parameter to list_comments.php, which triggers an injection in libraries.inc.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0760">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:eqdkp:eqdkp:1.3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:eqdkp:eqdkp:1.3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0760</vuln:cve-id>
    <vuln:published-datetime>2007-02-05T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:04.300-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/20805" xml:lang="en">20805</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32152" xml:lang="en">eqdkp-backup-information-disclosure(32152)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3252" xml:lang="en">3252</vuln:reference>
    </vuln:references>
    <vuln:summary>EQdkp 1.3.1 and earlier authenticates administrative requests by verifying that the HTTP Referer header specifies an admin/ URL, which allows remote attackers to read or modify account names and passwords via a spoofed Referer.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0761">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpbb:ezboard_converter:0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpbb:ezboard_converter:0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0761</vuln:cve-id>
    <vuln:published-datetime>2007-02-05T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:04.410-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-February/001278.html" xml:lang="en">20070202 true: phpBB ezBoard converter 0.2 (ezconvert_dir) Remote File Include Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0473" xml:lang="en">ADV-2007-0473</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.xoron.info/bugs/ezconvert.txt" xml:lang="en">http://www.xoron.info/bugs/ezconvert.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32157" xml:lang="en">ezboard-config-file-include(32157)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3258" xml:lang="en">3258</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in config.php in phpBB ezBoard converter (ezconvert) 0.2 allows remote attackers to execute arbitrary PHP code via a URL in the ezconvert_dir parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0762">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpbb%2b%2b:phpbb%2b%2b:build_100"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpbb%2b%2b:phpbb%2b%2b:build_100</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0762</vuln:cve-id>
    <vuln:published-datetime>2007-02-05T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:04.473-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-February/001279.html" xml:lang="en">20070202 phpBB++ Build 100 (phpbb_root_path) Remote File Include Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22376" xml:lang="en">22376</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0472" xml:lang="en">ADV-2007-0472</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32159" xml:lang="en">phpbbplusplus-functions-file-include(32159)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3259" xml:lang="en">3259</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in includes/functions.php in phpBB++ Build 100 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0763">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:f3site:f3site:2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:f3site:f3site:2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0763</vuln:cve-id>
    <vuln:published-datetime>2007-02-05T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:04.537-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22379" xml:lang="en">22379</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32188" xml:lang="en">f3site-autor-xss(32188)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3255" xml:lang="en">3255</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the news comment functionality in F3Site 2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the Autor field.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0764">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:f3site:f3site:2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:f3site:f3site:2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0764</vuln:cve-id>
    <vuln:published-datetime>2007-02-05T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:04.613-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32189" xml:lang="en">f3site-adm-file-upload(32189)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3255" xml:lang="en">3255</vuln:reference>
    </vuln:references>
    <vuln:summary>Unrestricted file upload vulnerability in F3Site 2.1 and earlier allows remote authenticated administrators to upload and execute arbitrary PHP scripts via GIF86 header in a file in the uplf parameter, which can be later accessed via a relative pathname in the dir parameter in adm.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0765">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:db_masters_multimedia:curium_cms:1.03"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:db_masters_multimedia:curium_cms:1.03</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0765</vuln:cve-id>
    <vuln:published-datetime>2007-02-05T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:04.737-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22373" xml:lang="en">22373</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0474" xml:lang="en">ADV-2007-0474</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32148" xml:lang="en">curium-news-sql-injection(32148)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3256" xml:lang="en">3256</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in news.php in dB Masters Curium CMS 1.03 and earlier allows remote attackers to execute arbitrary SQL commands via the c_id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0766">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:remotesoft:.net_explorer:2.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:remotesoft:.net_explorer:2.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0766</vuln:cve-id>
    <vuln:published-datetime>2007-02-05T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:04.787-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22377" xml:lang="en">22377</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32182" xml:lang="en">netexplorer-char-bo(32182)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3254" xml:lang="en">3254</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in Remotesoft .NET Explorer 2.0.1 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long line in a .cpp file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0767">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phorum:phorum:5.1.17"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phorum:phorum:5.1.17</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0767</vuln:cve-id>
    <vuln:published-datetime>2007-02-05T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:23.970-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.phorum.org/phorum5/read.php?12,119757" xml:lang="en">http://www.phorum.org/phorum5/read.php?12,119757</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0410" xml:lang="en">ADV-2007-0410</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/44201" xml:lang="en">phorum-core-xss(44201)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the core in Phorum before 5.1.18 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0768">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:yahoo:messenger:8.1.0.209"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:yahoo:messenger:8.1.0.209</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0768</vuln:cve-id>
    <vuln:published-datetime>2007-02-05T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:05.777-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458225/100/0/threaded" xml:lang="en">20070126 Cross-site Scripting with Local Privilege Vulnerability in Yahoo Messenger</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458305/100/0/threaded" xml:lang="en">20070127 RE: Cross-site Scripting with Local Privilege Vulnerability in Yahoo Messenger</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458494/100/0/threaded" xml:lang="en">20070127 Re: Cross-site Scripting with Local Privilege Vulnerability in Yahoo Messenger</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22269" xml:lang="en">22269</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in the Contact Details functionality in Yahoo! Messenger 8.1.0.209 and earlier allow user-assisted remote attackers to inject arbitrary web script or HTML via a javascript: URI in the SRC attribute of an IMG element to the (1) First Name, (2) Last Name, and (3) Nickname fields.  NOTE: some of these details are obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0769">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phorum:phorum:5.1.18"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phorum:phorum:5.1.18</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0769</vuln:cve-id>
    <vuln:published-datetime>2007-02-05T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:06.263-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.phorum.org/phorum5/read.php?12,119757" xml:lang="en">http://www.phorum.org/phorum5/read.php?12,119757</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458461/100/0/threaded" xml:lang="en">20070129 Phorum HTML Injection Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458467/100/0/threaded" xml:lang="en">20070129 Re: Phorum HTML Injection Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22297" xml:lang="en">22297</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0410" xml:lang="en">ADV-2007-0410</vuln:reference>
    </vuln:references>
    <vuln:summary>** DISPUTED **  Cross-site scripting (XSS) vulnerability in register.php in Phorum 5.1.18 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: the vendor disputes this vulnerability, stating that "The characters are escaped properly."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0770">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:graphicsmagick:graphicsmagick"/>
        <cpe-lang:fact-ref name="cpe:/a:imagemagick:imagemagick:6.3.3.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:graphicsmagick:graphicsmagick</vuln:product>
      <vuln:product>cpe:/a:imagemagick:imagemagick:6.3.3.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0770</vuln:cve-id>
    <vuln:published-datetime>2007-02-12T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:06.623-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1260" xml:lang="en">DSA-1260</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:041" xml:lang="en">MDKSA-2007:041</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_3_sr.html" xml:lang="en">SUSE-SR:2007:003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459507/100/0/threaded" xml:lang="en">20070208 rPSA-2007-0029-1 ImageMagick</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-422-1" xml:lang="en">USN-422-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1034" xml:lang="en">https://issues.rpath.com/browse/RPL-1034</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in GraphicsMagick and ImageMagick allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a PALM image that is not properly handled by the ReadPALMImage function in coders/palm.c. NOTE: this issue is due to an incomplete patch for CVE-2006-5456.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0771">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.4"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:5.0::desktop"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:5.0::desktop_workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:5.0::server"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.4</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:5.0::desktop</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:5.0::desktop_workstation</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:5.0::server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0771</vuln:cve-id>
    <vuln:published-datetime>2007-05-02T18:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:38.750-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9447" name="oval:org.mitre.oval:def:9447"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017979" xml:lang="en">1017979</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0169.html" xml:lang="en">RHSA-2007:0169</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23720" xml:lang="en">23720</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=227952" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=227952</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.redhat.com/show_bug.cgi?id=228816" xml:lang="en">https://bugzilla.redhat.com/show_bug.cgi?id=228816</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/34128" xml:lang="en">kernel-utracesupport-dos(34128)</vuln:reference>
    </vuln:references>
    <vuln:summary>The utrace support in Linux kernel 2.6.18, and other versions, allows local users to cause a denial of service (system hang) related to "MT exec + utrace_attach spin failure mode," as demonstrated by ptrace-thrash.c.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0772">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.25"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.26"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.28"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.29"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.30"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.31"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.32"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.33"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.34"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.35"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.36"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.37"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.38"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.39"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.40"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.41"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.42"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.43"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.44"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.45"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.46"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.47"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.48"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.49"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.50"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.51"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.52"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.53"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.54"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.55"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.56"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.57"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.59"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.60"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.61"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.62"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.25</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.26</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.28</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.29</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.30</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.31</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.32</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.33</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.34</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.35</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.36</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.37</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.38</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.39</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.40</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.41</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.42</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.43</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.44</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.45</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.46</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.47</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.48</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.49</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.50</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.51</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.52</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.53</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.54</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.55</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.56</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.57</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.59</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.60</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.61</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.62</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0772</vuln:cve-id>
    <vuln:published-datetime>2007-02-20T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:24.110-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20.1" xml:lang="en">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:060" xml:lang="en">MDKSA-2007:060</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:078" xml:lang="en">MDKSA-2007:078</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_18_kernel.html" xml:lang="en">SUSE-SA:2007:018</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_21_kernel.html" xml:lang="en">SUSE-SA:2007:021</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/471457" xml:lang="en">20070615 rPSA-2007-0124-1 kernel xen</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22625" xml:lang="en">22625</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-451-1" xml:lang="en">USN-451-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0660" xml:lang="en">ADV-2007-0660</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32578" xml:lang="en">kernel-nfsaclsvc-dos(32578)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1063" xml:lang="en">https://issues.rpath.com/browse/RPL-1063</vuln:reference>
    </vuln:references>
    <vuln:summary>The Linux kernel 2.6.13 and other versions before 2.6.20.1 allows remote attackers to cause a denial of service (oops) via a crafted NFSACL 2 ACCESS request that triggers a free of an incorrect pointer.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0773">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.4::as"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.4::es"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.4::ws"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_desktop:4.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:redhat:enterprise_linux:4.4::as</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:4.4::es</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:4.4::ws</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux_desktop:4.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0773</vuln:cve-id>
    <vuln:published-datetime>2007-06-26T14:30:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:38.813-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11267" name="oval:org.mitre.oval:def:11267"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=243252" xml:lang="en">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=243252</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2007-0488.html" xml:lang="en">RHSA-2007:0488</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2007-287.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2007-287.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_53_kernel.html" xml:lang="en">SUSE-SA:2007:053</vuln:reference>
    </vuln:references>
    <vuln:summary>The Linux kernel before 2.6.9-42.0.8 in Red Hat 4.4 allows local users to cause a denial of service (kernel OOPS from null dereference) via fput in a 32-bit ioctl on 64-bit x86 systems, an incomplete fix of CVE-2005-3044.1.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0774">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat_jk_web_server_connector:1.2.19"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat_jk_web_server_connector:1.2.20"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:tomcat_jk_web_server_connector:1.2.19</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat_jk_web_server_connector:1.2.20</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0774</vuln:cve-id>
    <vuln:published-datetime>2007-03-04T17:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-04-15T12:29:08.287-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5513" name="oval:org.mitre.oval:def:5513"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795" xml:lang="en">SSRT071447</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017719" xml:lang="en">1017719</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://tomcat.apache.org/connectors-doc/miscellaneous/changelog.html" xml:lang="en">http://tomcat.apache.org/connectors-doc/miscellaneous/changelog.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://tomcat.apache.org/security-jk.html" xml:lang="en">http://tomcat.apache.org/security-jk.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/en/US/products/products_security_advisory09186a008093f040.shtml" xml:lang="en">20080130 Cisco Wireless Control System Tomcat mod_jk.so Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200703-16.xml" xml:lang="en">GLSA-200703-16</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0096.html" xml:lang="en">RHSA-2007:0096</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461734/100/0/threaded" xml:lang="en">20070302 ZDI-07-008: Apache Tomcat JK Web Server Connector Long URL Stack Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22791" xml:lang="en">22791</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0809" xml:lang="en">ADV-2007-0809</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/3386" xml:lang="en">ADV-2007-3386</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0331" xml:lang="en">ADV-2008-0331</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-07-008.html" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-07-008.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32794" xml:lang="en">tomcat-mapuritoworker-bo(32794)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.apache.org/thread.html/277d42b48b6e9aef50949c0dcc79ce21693091d73da246b3c1981925@%3Cdev.tomcat.apache.org%3E" xml:lang="en">[tomcat-dev] 20190413 svn commit: r1857494 [18/20] - in /tomcat/site/trunk: ./ docs/ xdocs/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.apache.org/thread.html/5b7a23e245c93235c503900da854a143596d901bf1a1f67e851a5de4@%3Cdev.tomcat.apache.org%3E" xml:lang="en">[tomcat-dev] 20190415 svn commit: r1857582 [20/22] - in /tomcat/site/trunk: docs/ xdocs/stylesheets/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.apache.org/thread.html/8d2a579bbd977c225c70cb23b0ec54865fb0dab5da3eff1e060c9935@%3Cdev.tomcat.apache.org%3E" xml:lang="en">[tomcat-dev] 20190325 svn commit: r1856174 [25/29] - in /tomcat/site/trunk: docs/ xdocs/ xdocs/stylesheets/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="https://lists.apache.org/thread.html/ba661b0edd913b39ff129a32d855620dd861883ade05fd88a8ce517d@%3Cdev.tomcat.apache.org%3E" xml:lang="en">[tomcat-dev] 20190319 svn commit: r1855831 [26/30] - in /tomcat/site/trunk: ./ docs/ xdocs/</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in the map_uri_to_worker function (native/common/jk_uri_worker_map.c) in mod_jk.so for Apache Tomcat JK Web Server Connector 1.2.19 and 1.2.20, as used in Tomcat 4.1.34 and 5.5.20, allows remote attackers to execute arbitrary code via a long URL that triggers the overflow in a URI worker map routine.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0775">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.6::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0:beta_1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0::alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:firefox:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.6::linux</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0:beta_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0:rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0:rc3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0::alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0775</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T14:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:08.637-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.7</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10012" name="oval:org.mitre.oval:def:10012"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc" xml:lang="en">20070202-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" xml:lang="en">20070301-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2713" xml:lang="en">FEDORA-2007-281</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2728" xml:lang="en">FEDORA-2007-293</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2747" xml:lang="en">FEDORA-2007-308</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2749" xml:lang="en">FEDORA-2007-309</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" xml:lang="en">HPSBUX02153</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html" xml:lang="en">SUSE-SA:2007:019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2007-0077.html" xml:lang="en">RHSA-2007:0077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200703-04.xml" xml:lang="en">GLSA-200703-04</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200703-18.xml" xml:lang="en">GLSA-200703-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131" xml:lang="en">SSA:2007-066-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.363947" xml:lang="en">SSA:2007-066-04</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.374851" xml:lang="en">SSA:2007-066-03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1336" xml:lang="en">DSA-1336</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml" xml:lang="en">GLSA-200703-08</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/761756" xml:lang="en">VU#761756</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:050" xml:lang="en">MDKSA-2007:050</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:052" xml:lang="en">MDKSA-2007:052</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2007/mfsa2007-01.html" xml:lang="en">http://www.mozilla.org/security/announce/2007/mfsa2007-01.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html" xml:lang="en">SUSE-SA:2007:022</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0078.html" xml:lang="en">RHSA-2007:0078</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0079.html" xml:lang="en">RHSA-2007:0079</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0097.html" xml:lang="en">RHSA-2007:0097</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0108.html" xml:lang="en">RHSA-2007:0108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461336/100/0/threaded" xml:lang="en">20070226 rPSA-2007-0040-1 firefox</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461809/100/0/threaded" xml:lang="en">20070303 rPSA-2007-0040-3 firefox thunderbird</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22694" xml:lang="en">22694</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017698" xml:lang="en">1017698</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-428-1" xml:lang="en">USN-428-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-431-1" xml:lang="en">USN-431-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0718" xml:lang="en">ADV-2007-0718</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0719" xml:lang="en">ADV-2007-0719</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0083" xml:lang="en">ADV-2008-0083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32704" xml:lang="en">mozilla-multiple-layout-code-execution(32704)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1081" xml:lang="en">https://issues.rpath.com/browse/RPL-1081</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1103" xml:lang="en">https://issues.rpath.com/browse/RPL-1103</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple unspecified vulnerabilities in the layout engine in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1.0.8 allow remote attackers to cause a denial of service (crash) and potentially execute arbitrary code via certain vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0776">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0776</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T14:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:15.387-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2713" xml:lang="en">FEDORA-2007-281</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2728" xml:lang="en">FEDORA-2007-293</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2747" xml:lang="en">FEDORA-2007-308</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2749" xml:lang="en">FEDORA-2007-309</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" xml:lang="en">HPSBUX02153</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html" xml:lang="en">SUSE-SA:2007:019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200703-04.xml" xml:lang="en">GLSA-200703-04</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200703-18.xml" xml:lang="en">GLSA-200703-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131" xml:lang="en">SSA:2007-066-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.363947" xml:lang="en">SSA:2007-066-04</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.374851" xml:lang="en">SSA:2007-066-03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml" xml:lang="en">GLSA-200703-08</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/551436" xml:lang="en">VU#551436</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:052" xml:lang="en">MDKSA-2007:052</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2007/mfsa2007-01.html" xml:lang="en">http://www.mozilla.org/security/announce/2007/mfsa2007-01.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html" xml:lang="en">SUSE-SA:2007:022</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461336/100/0/threaded" xml:lang="en">20070226 rPSA-2007-0040-1 firefox</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461809/100/0/threaded" xml:lang="en">20070303 rPSA-2007-0040-3 firefox thunderbird</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22694" xml:lang="en">22694</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017698" xml:lang="en">1017698</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-428-1" xml:lang="en">USN-428-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-431-1" xml:lang="en">USN-431-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0718" xml:lang="en">ADV-2007-0718</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0719" xml:lang="en">ADV-2007-0719</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0083" xml:lang="en">ADV-2008-0083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=360645" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=360645</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32698" xml:lang="en">firefox-strokewidth-bo(32698)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1081" xml:lang="en">https://issues.rpath.com/browse/RPL-1081</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in the _cairo_pen_init function in Mozilla Firefox 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1.0.8 allows remote attackers to execute arbitrary code via a large stroke-width attribute in the clipPath element in an SVG file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0777">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:-"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:-"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7:-"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7:rc"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0:-"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0:rc"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.1:alpha1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.1:alpha2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5:-"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:5.10"/>
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:6.06::~~lts~~~"/>
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:6.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:firefox:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:-</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:-</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7:-</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7:rc</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0:-</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0:rc</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.1:alpha1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.1:alpha2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5:-</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5:beta1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5:beta2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5:rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.9</vuln:product>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:5.10</vuln:product>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:6.06::~~lts~~~</vuln:product>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:6.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0777</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T14:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-10-09T18:52:10.710-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11331" name="oval:org.mitre.oval:def:11331"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc" xml:lang="en">20070202-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" xml:lang="en">20070301-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2713" xml:lang="en">FEDORA-2007-281</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2728" xml:lang="en">FEDORA-2007-293</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2747" xml:lang="en">FEDORA-2007-308</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2749" xml:lang="en">FEDORA-2007-309</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" xml:lang="en">HPSBUX02153</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html" xml:lang="en">SUSE-SA:2007:019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2007-0077.html" xml:lang="en">RHSA-2007:0077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200703-04.xml" xml:lang="en">GLSA-200703-04</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200703-18.xml" xml:lang="en">GLSA-200703-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131" xml:lang="en">SSA:2007-066-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.363947" xml:lang="en">SSA:2007-066-04</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.374851" xml:lang="en">SSA:2007-066-03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml" xml:lang="en">GLSA-200703-08</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/269484" xml:lang="en">VU#269484</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:050" xml:lang="en">MDKSA-2007:050</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:052" xml:lang="en">MDKSA-2007:052</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2007/mfsa2007-01.html" xml:lang="en">http://www.mozilla.org/security/announce/2007/mfsa2007-01.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html" xml:lang="en">SUSE-SA:2007:022</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0078.html" xml:lang="en">RHSA-2007:0078</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0079.html" xml:lang="en">RHSA-2007:0079</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0097.html" xml:lang="en">RHSA-2007:0097</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0108.html" xml:lang="en">RHSA-2007:0108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461336/100/0/threaded" xml:lang="en">20070226 rPSA-2007-0040-1 firefox</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461809/100/0/threaded" xml:lang="en">20070303 rPSA-2007-0040-3 firefox thunderbird</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22694" xml:lang="en">22694</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017698" xml:lang="en">1017698</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-428-1" xml:lang="en">USN-428-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-431-1" xml:lang="en">USN-431-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0718" xml:lang="en">ADV-2007-0718</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0719" xml:lang="en">ADV-2007-0719</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0083" xml:lang="en">ADV-2008-0083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32699" xml:lang="en">mozilla-multiple-javascript-code-execution(32699)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1081" xml:lang="en">https://issues.rpath.com/browse/RPL-1081</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1103" xml:lang="en">https://issues.rpath.com/browse/RPL-1103</vuln:reference>
    </vuln:references>
    <vuln:summary>The JavaScript engine in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1.0.8 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain vectors that trigger memory corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0778">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:-"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:5.10"/>
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:6.06::~~lts~~~"/>
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:6.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:firefox:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:-</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:5.10</vuln:product>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:6.06::~~lts~~~</vuln:product>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:6.10</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0778</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-10-09T18:52:10.927-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9151" name="oval:org.mitre.oval:def:9151"/>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc" xml:lang="en">20070202-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" xml:lang="en">20070301-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2713" xml:lang="en">FEDORA-2007-281</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2728" xml:lang="en">FEDORA-2007-293</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" xml:lang="en">HPSBUX02153</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html" xml:lang="en">SUSE-SA:2007:019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2007-0077.html" xml:lang="en">RHSA-2007:0077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200703-04.xml" xml:lang="en">GLSA-200703-04</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017699" xml:lang="en">1017699</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131" xml:lang="en">SSA:2007-066-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.374851" xml:lang="en">SSA:2007-066-03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1336" xml:lang="en">DSA-1336</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml" xml:lang="en">GLSA-200703-08</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:050" xml:lang="en">MDKSA-2007:050</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2007/mfsa2007-03.html" xml:lang="en">http://www.mozilla.org/security/announce/2007/mfsa2007-03.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html" xml:lang="en">SUSE-SA:2007:022</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0078.html" xml:lang="en">RHSA-2007:0078</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0079.html" xml:lang="en">RHSA-2007:0079</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0097.html" xml:lang="en">RHSA-2007:0097</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0108.html" xml:lang="en">RHSA-2007:0108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461336/100/0/threaded" xml:lang="en">20070226 rPSA-2007-0040-1 firefox</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461809/100/0/threaded" xml:lang="en">20070303 rPSA-2007-0040-3 firefox thunderbird</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22694" xml:lang="en">22694</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-428-1" xml:lang="en">USN-428-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0718" xml:lang="en">ADV-2007-0718</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0083" xml:lang="en">ADV-2008-0083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=347852" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=347852</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32671" xml:lang="en">mozilla-diskcache-information-disclosure(32671)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1081" xml:lang="en">https://issues.rpath.com/browse/RPL-1081</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1103" xml:lang="en">https://issues.rpath.com/browse/RPL-1103</vuln:reference>
    </vuln:references>
    <vuln:summary>The page cache feature in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 can generate hash collisions that cause page data to be appended to the wrong page cache, which allows remote attackers to obtain sensitive information or enable further attack vectors when the target page is reloaded from the cache.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0779">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9_rc"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0:beta_1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0::alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0::dev"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.99"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:firefox:0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9_rc</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.10.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0:beta_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0:rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0:rc3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0::alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0::dev</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.99</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0779</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:30.840-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8757" name="oval:org.mitre.oval:def:8757"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc" xml:lang="en">20070202-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" xml:lang="en">20070301-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2713" xml:lang="en">FEDORA-2007-281</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2728" xml:lang="en">FEDORA-2007-293</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" xml:lang="en">HPSBUX02153</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html" xml:lang="en">SUSE-SA:2007:019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2007-0077.html" xml:lang="en">RHSA-2007:0077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200703-04.xml" xml:lang="en">GLSA-200703-04</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131" xml:lang="en">SSA:2007-066-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.374851" xml:lang="en">SSA:2007-066-03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml" xml:lang="en">GLSA-200703-08</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:050" xml:lang="en">MDKSA-2007:050</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2007/mfsa2007-04.html" xml:lang="en">http://www.mozilla.org/security/announce/2007/mfsa2007-04.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html" xml:lang="en">SUSE-SA:2007:022</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0078.html" xml:lang="en">RHSA-2007:0078</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0079.html" xml:lang="en">RHSA-2007:0079</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0097.html" xml:lang="en">RHSA-2007:0097</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0108.html" xml:lang="en">RHSA-2007:0108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461336/100/0/threaded" xml:lang="en">20070226 rPSA-2007-0040-1 firefox</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461809/100/0/threaded" xml:lang="en">20070303 rPSA-2007-0040-3 firefox thunderbird</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22694" xml:lang="en">22694</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017700" xml:lang="en">1017700</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-428-1" xml:lang="en">USN-428-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0718" xml:lang="en">ADV-2007-0718</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0083" xml:lang="en">ADV-2008-0083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=361298" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=361298</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1081" xml:lang="en">https://issues.rpath.com/browse/RPL-1081</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1103" xml:lang="en">https://issues.rpath.com/browse/RPL-1103</vuln:reference>
    </vuln:references>
    <vuln:summary>GUI overlay vulnerability in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 allows remote attackers to spoof certain user interface elements, such as the host name or security indicators, via the CSS3 hotspot property with a large, transparent, custom cursor.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0780">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:-"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:5.10"/>
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:6.06::~~lts~~~"/>
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:6.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:firefox:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:-</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:5.10</vuln:product>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:6.06::~~lts~~~</vuln:product>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:6.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0780</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-10-09T18:52:11.163-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9884" name="oval:org.mitre.oval:def:9884"/>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc" xml:lang="en">20070202-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" xml:lang="en">20070301-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2713" xml:lang="en">FEDORA-2007-281</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2728" xml:lang="en">FEDORA-2007-293</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" xml:lang="en">HPSBUX02153</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html" xml:lang="en">SUSE-SA:2007:019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2007-0077.html" xml:lang="en">RHSA-2007:0077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200703-04.xml" xml:lang="en">GLSA-200703-04</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131" xml:lang="en">SSA:2007-066-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.374851" xml:lang="en">SSA:2007-066-03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml" xml:lang="en">GLSA-200703-08</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:050" xml:lang="en">MDKSA-2007:050</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2007/mfsa2007-05.html" xml:lang="en">http://www.mozilla.org/security/announce/2007/mfsa2007-05.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html" xml:lang="en">SUSE-SA:2007:022</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0078.html" xml:lang="en">RHSA-2007:0078</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0079.html" xml:lang="en">RHSA-2007:0079</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0097.html" xml:lang="en">RHSA-2007:0097</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0108.html" xml:lang="en">RHSA-2007:0108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461336/100/0/threaded" xml:lang="en">20070226 rPSA-2007-0040-1 firefox</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461809/100/0/threaded" xml:lang="en">20070303 rPSA-2007-0040-3 firefox thunderbird</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22694" xml:lang="en">22694</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017702" xml:lang="en">1017702</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-428-1" xml:lang="en">USN-428-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0718" xml:lang="en">ADV-2007-0718</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=354973" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=354973</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32667" xml:lang="en">mozilla-dataurl-xss(32667)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1081" xml:lang="en">https://issues.rpath.com/browse/RPL-1081</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1103" xml:lang="en">https://issues.rpath.com/browse/RPL-1103</vuln:reference>
    </vuln:references>
    <vuln:summary>browser.js in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 uses the requesting URI to identify child windows, which allows remote attackers to conduct cross-site scripting (XSS) attacks by opening a blocked popup originating from a javascript: URI in combination with multiple frames having the same data: URI.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0784">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:rbl:tpassword"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rbl:tpassword</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0784</vuln:cve-id>
    <vuln:published-datetime>2007-02-06T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:40.637-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://forums.avenir-geopolitique.net/viewtopic.php?t=2607" xml:lang="en">http://forums.avenir-geopolitique.net/viewtopic.php?t=2607</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2225" xml:lang="en">2225</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-January/001259.html" xml:lang="en">20070131 Partial source code verify - "RBL - ASP" scripts SQL injection</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458495/100/0/threaded" xml:lang="en">20070127 RBL - ASP (scripts with db) SQL injection</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458560/100/0/threaded" xml:lang="en">20070129 RBL - ASP (scripts with db) SQL injection</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in login.asp for tPassword in the Raymond BERTHOU script collection (aka RBL - ASP) allows remote attackers to execute arbitrary SQL commands via the (1) User and (2) Password parameters.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0785">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:flipsource:flip:2.01-final_1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:flipsource:flip:2.01-final_1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0785</vuln:cve-id>
    <vuln:published-datetime>2007-02-06T14:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:04.847-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22385" xml:lang="en">22385</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0476" xml:lang="en">ADV-2007-0476</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32174" xml:lang="en">flip-previewtheme-file-include(32174)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3266" xml:lang="en">3266</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in previewtheme.php in Flipsource Flip 2.01-final 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the inc_path parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0786">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:noname_media:photo_galerie_standard:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:noname_media:photo_galerie_standard:1.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:noname_media:photo_galerie_standard:1.1</vuln:product>
      <vuln:product>cpe:/a:noname_media:photo_galerie_standard:1.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0786</vuln:cve-id>
    <vuln:published-datetime>2007-02-06T14:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:04.910-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22384" xml:lang="en">22384</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0475" xml:lang="en">ADV-2007-0475</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32171" xml:lang="en">photogalerie-view-sql-injection(32171)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3261" xml:lang="en">3261</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in view.php in Noname Media Photo Galerie Standard 1.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0787">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:simple_invoices:simple_invoices:2007-02-02"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:simple_invoices:simple_invoices:2007-02-02</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0787</vuln:cve-id>
    <vuln:published-datetime>2007-02-06T14:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:24.860-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22389" xml:lang="en">22389</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.simpleinvoices.org/index.php?news=25" xml:lang="en">http://www.simpleinvoices.org/index.php?news=25</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0481" xml:lang="en">ADV-2007-0481</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32207" xml:lang="en">simpleinvoices-controller-file-include(32207)</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in controller.php in Simple Invoices before 20070202 allows remote attackers to execute arbitrary PHP code via a URL in the (1) module or (2) view parameter.  NOTE: some of these details are obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0788">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.9.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.9.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.9.0:rc2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.9.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0788</vuln:cve-id>
    <vuln:published-datetime>2007-02-06T14:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:24.907-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.wikimedia.org/pipermail/mediawiki-announce/2007-February/000059.html" xml:lang="en">[MediaWiki-announce] 20070204 MediaWiki 1.9.2 released</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_9_2/phase3/RELEASE-NOTES" xml:lang="en">http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_9_2/phase3/RELEASE-NOTES</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22397" xml:lang="en">22397</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0490" xml:lang="en">ADV-2007-0490</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32217" xml:lang="en">mediawiki-sortabletable-xss(32217)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in MediaWiki 1.9.x before 1.9.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "sortable tables JavaScript."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0789">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mambo:mambo:4.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mambo:mambo:4.5.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0789</vuln:cve-id>
    <vuln:published-datetime>2007-02-06T14:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-08-05T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-02-06T17:36:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0480" xml:lang="en">ADV-2007-0480</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in Mambo before 4.5.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors in cancel edit functions, possibly related to the id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0790">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:smartftp:smartftp:2.0.1002"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:smartftp:smartftp:2.0.1002</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0790</vuln:cve-id>
    <vuln:published-datetime>2007-02-06T14:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:39.610-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22390" xml:lang="en">22390</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32214" xml:lang="en">smartftp-banner-bo(32214)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3277" xml:lang="en">3277</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in SmartFTP 2.0.1002 allows remote FTP servers to execute arbitrary code via a large banner.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0791">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.20.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.20.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.20.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.21"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.21.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.21.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.22"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.22:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.22.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.23.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.23.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.20.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.20.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.20.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.21</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.21.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.21.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.22</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.22:rc1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.22.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.23.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.23.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0791</vuln:cve-id>
    <vuln:published-datetime>2007-02-06T14:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:40.997-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2222" xml:lang="en">2222</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017585" xml:lang="en">1017585</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.bugzilla.org/security/2.20.3/" xml:lang="en">http://www.bugzilla.org/security/2.20.3/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459025/100/0/threaded" xml:lang="en">20070203 Security Advisory for Bugzilla 2.20.3, 2.22.1, and 2.23.3</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22380" xml:lang="en">22380</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0477" xml:lang="en">ADV-2007-0477</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32248" xml:lang="en">bugzilla-atom-feed-xss(32248)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Atom feeds in Bugzilla 2.20.3, 2.22.1, and 2.23.3, and earlier versions down to 2.20.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0792">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:bugzilla:2.23.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:bugzilla:2.23.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0792</vuln:cve-id>
    <vuln:published-datetime>2007-02-06T14:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:41.637-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2222" xml:lang="en">2222</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017585" xml:lang="en">1017585</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.bugzilla.org/security/2.20.3/" xml:lang="en">http://www.bugzilla.org/security/2.20.3/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459025/100/0/threaded" xml:lang="en">20070203 Security Advisory for Bugzilla 2.20.3, 2.22.1, and 2.23.3</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22380" xml:lang="en">22380</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0477" xml:lang="en">ADV-2007-0477</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32252" xml:lang="en">bugzilla-htaccess-information-disclosure(32252)</vuln:reference>
    </vuln:references>
    <vuln:summary>The mod_perl initialization script in Bugzilla 2.23.3 does not set the Bugzilla Apache configuration to allow .htaccess permissions to override file permissions, which allows remote attackers to obtain the database username and password via a direct request for the localconfig file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0793">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:globalmegacorp:dvddb:0.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:globalmegacorp:dvddb:0.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0793</vuln:cve-id>
    <vuln:published-datetime>2007-02-06T14:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:42.200-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2221" xml:lang="en">2221</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459149/100/0/threaded" xml:lang="en">20070204 dvddb-0.6 media remote file include vuln.</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in inc/common.php in GlobalMegaCorp dvddb 0.6 allows remote attackers to execute arbitrary PHP code via a URL in the config parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0794">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:globalmegacorp:dvddb:0.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:globalmegacorp:dvddb:0.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0794</vuln:cve-id>
    <vuln:published-datetime>2007-02-06T14:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:42.420-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459151/100/0/threaded" xml:lang="en">20070204 dvddb-0.6 media sql-inj. vuln.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459180/100/0/threaded" xml:lang="en">20070205 Re: dvddb-0.6 media sql-inj. vuln.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/481327/100/100/threaded" xml:lang="en">20071002 Re: dvddb-0.6 media sql-inj. vuln.</vuln:reference>
    </vuln:references>
    <vuln:summary>** DISPUTED **  SQL injection vulnerability in inc/common.php in GlobalMegaCorp dvddb 0.6 allows remote attackers to execute arbitrary SQL commands via the user parameter.  NOTE: this issue has been disputed by a reliable third party, who states that inc/common.php only contains function definitions.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0795">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:wap:wap_portal_server:1.x"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wap:wap_portal_server:1.x</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0795</vuln:cve-id>
    <vuln:published-datetime>2007-02-06T14:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:42.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2216" xml:lang="en">2216</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459147/100/0/threaded" xml:lang="en">20070203 Wap Portal Serve 1.* &lt;= Remote File Inclusion</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32196" xml:lang="en">wapportal-index-file-include(32196)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple PHP remote file inclusion vulnerabilities in Wap Portal Server 1.x allow remote attackers to execute arbitrary PHP code via a URL in the language parameter to (1) index.php and (2) admin/index.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0796">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bluecoat:winproxy:6.0:r1c"/>
        <cpe-lang:fact-ref name="cpe:/a:bluecoat:winproxy:6.1:r1a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bluecoat:winproxy:6.0:r1c</vuln:product>
      <vuln:product>cpe:/a:bluecoat:winproxy:6.1:r1a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0796</vuln:cve-id>
    <vuln:published-datetime>2007-02-06T14:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:25.173-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=471" xml:lang="en">20070202 Blue Coat Systems WinProxy CONNECT Method Heap Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017586" xml:lang="en">1017586</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22393" xml:lang="en">22393</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0482" xml:lang="en">ADV-2007-0482</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32204" xml:lang="en">winproxy-connect-bo(32204)</vuln:reference>
    </vuln:references>
    <vuln:summary>Blue Coat Systems WinProxy 6.1a and 6.0 r1c, and possibly earlier, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long HTTP CONNECT request, which triggers heap corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0797">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bluevirus-design:sma-db:0.3.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bluevirus-design:sma-db:0.3.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0797</vuln:cve-id>
    <vuln:published-datetime>2007-02-06T14:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:04.957-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22391" xml:lang="en">22391</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0494" xml:lang="en">ADV-2007-0494</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32190" xml:lang="en">smadb-settings-file-include(32190)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3268" xml:lang="en">3268</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in theme/settings.php in bluevirus-design SMA-DB 0.3.9 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pfad_z parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0798">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:uapplication:ublog_reload:1.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:uapplication:ublog_reload:1.0.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0798</vuln:cve-id>
    <vuln:published-datetime>2007-02-06T14:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:43.233-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.hackerscenter.com/archive/view.asp?id=27270" xml:lang="en">http://www.hackerscenter.com/archive/view.asp?id=27270</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459027/100/0/threaded" xml:lang="en">20070203 Ublog Reload Admin Panel Multiple HTML Injections</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22382" xml:lang="en">22382</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32185" xml:lang="en">ublog-login-xss(32185)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Ublog Reload 1.0.5 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) login.asp; and allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters to (2) badword.asp, (3) polls.asp, and (4) users.asp.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0799">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:uapplication:ublog:reload_1.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:uapplication:ublog:reload_1.0.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0799</vuln:cve-id>
    <vuln:published-datetime>2007-02-06T14:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:43.793-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.hackerscenter.com/archive/view.asp?id=27270" xml:lang="en">http://www.hackerscenter.com/archive/view.asp?id=27270</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459027/100/0/threaded" xml:lang="en">20070203 Ublog Reload Admin Panel Multiple HTML Injections</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22382" xml:lang="en">22382</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32187" xml:lang="en">ublog-badword-sql-injection(32187)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in badword.asp in Ublog Reload 1.0.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0800">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0800</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:44.217-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10654" name="oval:org.mitre.oval:def:10654"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc" xml:lang="en">20070202-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" xml:lang="en">20070301-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2713" xml:lang="en">FEDORA-2007-281</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2728" xml:lang="en">FEDORA-2007-293</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" xml:lang="en">HPSBUX02153</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052209.html" xml:lang="en">20070205 Firefox + popup blocker + XMLHttpRequest + srand() = oops</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052211.html" xml:lang="en">20070205 Re: Firefox + popup blocker + XMLHttpRequest + srand() = oops</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html" xml:lang="en">SUSE-SA:2007:019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2007-0077.html" xml:lang="en">RHSA-2007:0077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200703-04.xml" xml:lang="en">GLSA-200703-04</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131" xml:lang="en">SSA:2007-066-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml" xml:lang="en">GLSA-200703-08</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:050" xml:lang="en">MDKSA-2007:050</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2007/mfsa2007-05.html" xml:lang="en">http://www.mozilla.org/security/announce/2007/mfsa2007-05.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html" xml:lang="en">SUSE-SA:2007:022</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0078.html" xml:lang="en">RHSA-2007:0078</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0079.html" xml:lang="en">RHSA-2007:0079</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0097.html" xml:lang="en">RHSA-2007:0097</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0108.html" xml:lang="en">RHSA-2007:0108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459162/100/0/threaded" xml:lang="en">20070205 Firefox + popup blocker + XMLHttpRequest + srand() = oops</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459163/100/0/threaded" xml:lang="en">20070205 Re: [Full-disclosure] Firefox + popup blocker + XMLHttpRequest + srand() = oops</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461336/100/0/threaded" xml:lang="en">20070226 rPSA-2007-0040-1 firefox</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461809/100/0/threaded" xml:lang="en">20070303 rPSA-2007-0040-3 firefox thunderbird</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22396" xml:lang="en">22396</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22694" xml:lang="en">22694</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017702" xml:lang="en">1017702</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-428-1" xml:lang="en">USN-428-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0718" xml:lang="en">ADV-2007-0718</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0083" xml:lang="en">ADV-2008-0083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32194" xml:lang="en">firefox-popup-security-bypass(32194)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1081" xml:lang="en">https://issues.rpath.com/browse/RPL-1081</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1103" xml:lang="en">https://issues.rpath.com/browse/RPL-1103</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-zone vulnerability in Mozilla Firefox 1.5.0.9 considers blocked popups to have an internal zone origin, which allows user-assisted remote attackers to cross zone restrictions and read arbitrary file:// URIs by convincing a user to show a blocked popup.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0801">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0801</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:49.170-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200703-04.xml" xml:lang="en">GLSA-200703-04</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml" xml:lang="en">GLSA-200703-08</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459162/100/0/threaded" xml:lang="en">20070205 Firefox + popup blocker + XMLHttpRequest + srand() = oops</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459163/100/0/threaded" xml:lang="en">20070205 Re: [Full-disclosure] Firefox + popup blocker + XMLHttpRequest + srand() = oops</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22396" xml:lang="en">22396</vuln:reference>
    </vuln:references>
    <vuln:summary>The nsExternalAppHandler::SetUpTempFile function in Mozilla Firefox 1.5.0.9 creates temporary files with predictable filenames based on creation time, which allows remote attackers to execute arbitrary web script or HTML via a crafted XMLHttpRequest.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0802">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:opera_software:opera:9.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.1</vuln:product>
      <vuln:product>cpe:/a:opera_software:opera:9.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0802</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:49.810-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-04/0516.html" xml:lang="en">20070418 Firefox 2.0.0.3 Phishing Protection Bypass Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://kaneda.bohater.net/security/20070111-firefox_2.0.0.1_bypass_phishing_protection.php" xml:lang="en">http://kaneda.bohater.net/security/20070111-firefox_2.0.0.1_bypass_phishing_protection.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459265/100/0/threaded" xml:lang="en">20070206 Firefox 2.0.0.1 and Opera 9.10 Anty Fraud/Phishing Protection bypass.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=367538" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=367538</vuln:reference>
    </vuln:references>
    <vuln:summary>Mozilla Firefox 2.0.0.1 allows remote attackers to bypass the Phishing Protection mechanism by adding certain characters to the end of the domain name, as demonstrated by the "." and "/" characters, which is not caught by the Phishing List blacklist filter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0803">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:stlport:stlport:5.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:stlport:stlport:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:stlport:stlport:5.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:stlport:stlport:5.0.0</vuln:product>
      <vuln:product>cpe:/a:stlport:stlport:5.0.1</vuln:product>
      <vuln:product>cpe:/a:stlport:stlport:5.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0803</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:25.500-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200703-07.xml" xml:lang="en">GLSA-200703-07</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=483468" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=483468</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22423" xml:lang="en">22423</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0498" xml:lang="en">ADV-2007-0498</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32242" xml:lang="en">stlport-printed-floats-bo(32242)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32244" xml:lang="en">stlport-rope-constructors-bo(32244)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in STLport before 5.0.3 allow remote attackers to execute arbitrary code via unspecified vectors relating to (1) "print floats" and (2) a missing null termination in the "rope constructor."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0804">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ggcms:ggcms:1.1.0_rc1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ggcms:ggcms:1.1.0_rc1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0804</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:05.020-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22412" xml:lang="en">22412</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0492" xml:lang="en">ADV-2007-0492</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32211" xml:lang="en">ggcms-subpages-code-execution(32211)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3271" xml:lang="en">3271</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in admin/subpages.php in GGCMS 1.1.0 RC1 and earlier allows remote attackers to inject arbitrary PHP code into arbitrary files via ".." sequences in the subpageName parameter, as demonstrated by injecting PHP code into a template file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0805">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:hp:tru64:5.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:tru64:5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0805</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:50.107-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00817515" xml:lang="en">HPSBTU02179</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052227.html" xml:lang="en">20070206 PS Information Leak on HP True64 Alpha OSF1 v5.1 1885</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://rawlab.mindcreations.com/codes/exp/nix/osf1tru64ps.ksh" xml:lang="en">http://rawlab.mindcreations.com/codes/exp/nix/osf1tru64ps.ksh</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017592" xml:lang="en">1017592</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459266/100/0/threaded" xml:lang="en">20070206 Re: [Full-disclosure] PS Information Leak on HP Tru64 Alpha OSF1v5.1 1885</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459275/100/0/threaded" xml:lang="en">20070206 PS Information Leak on HP True64 Alpha OSF1 v5.1 1885</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459593/100/200/threaded" xml:lang="en">20070207 Re: PS Information Leak on HP True64 Alpha OSF1 v5.1 1885</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018005" xml:lang="en">1018005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1654" xml:lang="en">ADV-2007-1654</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32276" xml:lang="en">tru64-ps-information-disclosure(32276)</vuln:reference>
    </vuln:references>
    <vuln:summary>The ps (/usr/ucb/ps) command on HP Tru64 UNIX 5.1 1885 allows local users to obtain sensitive information, including environment variables of arbitrary processes, via the "auxewww" argument, a similar issue to CVE-1999-1587.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0806">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:les_news:les_news:2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:les_news:les_news:2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0806</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:50.920-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://forums.avenir-geopolitique.net/viewtopic.php?t=2622" xml:lang="en">http://forums.avenir-geopolitique.net/viewtopic.php?t=2622</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2226" xml:lang="en">2226</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459186/100/0/threaded" xml:lang="en">20070204 Les News v2.2 [Admin news without password]</vuln:reference>
    </vuln:references>
    <vuln:summary>Les News 2.2 allows remote attackers to bypass authentication and gain administrative access via a direct request for adminews/index_fr.php3, and possibly the adminews index documents for other localizations.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0807">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:darrens_5-dollar_script_archive:flashchat:4.7.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:darrens_5-dollar_script_archive:flashchat:4.7.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0807</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:51.107-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2228" xml:lang="en">2228</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459160/100/0/threaded" xml:lang="en">20070205 flashChat 4.7.8 Cross Site Scripting Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22411" xml:lang="en">22411</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0495" xml:lang="en">ADV-2007-0495</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32208" xml:lang="en">flashchat-info-xss(32208)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in info.php in flashChat 4.7.8 allows remote attackers to inject arbitrary web script or HTML via a channel title (aka room name) that is not properly handled by the "who's online" feature.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0808">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mina_ajans:mina_ajans_script"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mina_ajans:mina_ajans_script</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0808</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:51.420-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459191/100/0/threaded" xml:lang="en">20070205 Mina Ajans Script Remote File Inclusion Vuln.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32243" xml:lang="en">mina-multiple-file-include(32243)</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in Mina Ajans Script allows remote attackers to execute arbitrary PHP code via a URL in the syf parameter to an unspecified PHP script.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0809">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ptirhiikmods:mod-ch:2.1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ptirhiikmods:mod-ch:2.1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0809</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:05.083-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://attrition.org/pipermail/vim/2007-February/001285.html" xml:lang="en">20070207 true: Categories hierarchy class_template.php RFI</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22400" xml:lang="en">22400</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0493" xml:lang="en">ADV-2007-0493</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32193" xml:lang="en">ch-classtemplate-file-include(32193)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3270" xml:lang="en">3270</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in includes/class_template.php in Categories hierarchy (aka CH or mod-CH) 2.1.2 in ptirhiikmods allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0810">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:geeklog:geeklog:2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:geeklog:geeklog:2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0810</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:05.127-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22386" xml:lang="en">22386</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32205" xml:lang="en">geeklog-baseview-file-include(32205)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3267" xml:lang="en">3267</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in MVCnPHP/BaseView.php in GeekLog 2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the glConf[path_libraries] parameter.  NOTE: this might be a vulnerability in MVCnPHP rather than a vulnerability in GeekLog.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0811">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6::windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp2:windows_xp"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:6::windows_2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp2:windows_xp</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0811</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:05.190-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.powerhacker.net/exploit/IE_NULL_CRASH.html" xml:lang="en">http://www.powerhacker.net/exploit/IE_NULL_CRASH.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22408" xml:lang="en">22408</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3272" xml:lang="en">3272</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Internet Explorer 6.0 SP1 on Windows 2000, and 6.0 SP2 on Windows XP, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an HTML document containing a certain JavaScript for loop with an empty loop body, possibly involving getElementById.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0812">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:woltlab:burning_board_lite:1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:woltlab:burning_board_lite:1.0.1e"/>
        <cpe-lang:fact-ref name="cpe:/a:woltlab:burning_board_lite:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:woltlab:burning_board_lite:1.0.2_pl3e"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:woltlab:burning_board_lite:1.0.0</vuln:product>
      <vuln:product>cpe:/a:woltlab:burning_board_lite:1.0.1e</vuln:product>
      <vuln:product>cpe:/a:woltlab:burning_board_lite:1.0.2</vuln:product>
      <vuln:product>cpe:/a:woltlab:burning_board_lite:1.0.2_pl3e</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0812</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:05.253-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22415" xml:lang="en">22415</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0491" xml:lang="en">ADV-2007-0491</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32172" xml:lang="en">wbblite-pms-sql-injection(32172)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3262" xml:lang="en">3262</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in pms.php in Woltlab Burning Board (wBB) Lite 1.0.2pl3e and earlier allows remote authenticated users to execute arbitrary SQL commands via the pmid[0] parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0813">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:home_production:mysearchengine"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:home_production:mysearchengine</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0813</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:51.607-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://forums.avenir-geopolitique.net/viewtopic.php?t=2621" xml:lang="en">http://forums.avenir-geopolitique.net/viewtopic.php?t=2621</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459145/100/0/threaded" xml:lang="en">20070204 MysearchEngine XSS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22402" xml:lang="en">22402</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32201" xml:lang="en">mysearchengine-search-xss(32201)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Home production MySearchEngine allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0814">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:adrenalin_labs:adrenalins_asp_chat"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adrenalin_labs:adrenalins_asp_chat</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0814</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:51.873-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://forums.avenir-geopolitique.net/viewtopic.php?t=2620" xml:lang="en">http://forums.avenir-geopolitique.net/viewtopic.php?t=2620</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2233" xml:lang="en">2233</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459144/100/0/threaded" xml:lang="en">20070203 Adrenalin's ASP Chat XSS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22392" xml:lang="en">22392</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32203" xml:lang="en">adrenalin-unspecified-script-xss(32203)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Adrenalin's ASP Chat allow remote attackers to inject arbitrary web script or HTML (1) via the psuedo (pseudo) field or (2) during chat.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0815">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:uapplication:uphotogallery:1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:uapplication:uphotogallery:1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0815</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:52.170-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2227" xml:lang="en">2227</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459187/100/0/threaded" xml:lang="en">20070204 Uphotogallery Multiple Cross-Site Scripting Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22404" xml:lang="en">22404</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32229" xml:lang="en">uphotogallery-imagesarchive-xss(32229)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in images_archive.asp in Uapplication Uphotogallery 1.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the s parameter.  NOTE: the thumbnails.asp vector is already covered by CVE-2006-3023.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0816">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ca:brightstor_arcserve_backup:11"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:brightstor_arcserve_backup:11.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:brightstor_arcserve_backup:11.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:brightstor_arcserve_backup:11.5:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:brightstor_arcserve_backup:11.5:sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ca:brightstor_arcserve_backup:11</vuln:product>
      <vuln:product>cpe:/a:ca:brightstor_arcserve_backup:11.1</vuln:product>
      <vuln:product>cpe:/a:ca:brightstor_arcserve_backup:11.5</vuln:product>
      <vuln:product>cpe:/a:ca:brightstor_arcserve_backup:11.5:sp1</vuln:product>
      <vuln:product>cpe:/a:ca:brightstor_arcserve_backup:11.5:sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0816</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:05.317-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://supportconnectw.ca.com/public/storage/infodocs/babtapeng-securitynotice.asp" xml:lang="en">http://supportconnectw.ca.com/public/storage/infodocs/babtapeng-securitynotice.asp</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22365" xml:lang="en">22365</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0461" xml:lang="en">ADV-2007-0461</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www3.ca.com/securityadvisor/newsinfo/collateral.aspx?cid=101317" xml:lang="en">http://www3.ca.com/securityadvisor/newsinfo/collateral.aspx?cid=101317</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=35058" xml:lang="en">http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=35058</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32137" xml:lang="en">brightstor-catirpc-dos(32137)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3248" xml:lang="en">3248</vuln:reference>
    </vuln:references>
    <vuln:summary>The RPC Server service (catirpc.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 SP2 and earlier allows remote attackers to cause a denial of service (service crash) via a crafted TADDR2UADDR that triggers a null pointer dereference in catirpc.dll, possibly related to null credentials or verifier fields.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0817">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:adobe:coldfusion:6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:coldfusion:7.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:coldfusion:7.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:coldfusion:6.1</vuln:product>
      <vuln:product>cpe:/a:adobe:coldfusion:7.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:coldfusion:7.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0817</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:52.467-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb07-04.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb07-04.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459178/100/0/threaded" xml:lang="en">20070205 Cold Fusion Web Server XSS 0 day</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22401" xml:lang="en">22401</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017645" xml:lang="en">1017645</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0593" xml:lang="en">ADV-2007-0593</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Adobe ColdFusion web server allows remote attackers to inject arbitrary HTML or web script via the User-Agent HTTP header, which is not sanitized before being displayed in an error page.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0818">
    <vuln:cve-id>CVE-2007-0818</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:50:05.103-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2007-0396.  Reason: This candidate is a duplicate of CVE-2007-0396.  Notes: All CVE users should reference CVE-2007-0396 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0819">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:hp:network_node_manager:7.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hp:network_node_manager:7.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0819</vuln:cve-id>
    <vuln:published-datetime>2007-02-08T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:26.140-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0174.html" xml:lang="en">20070208 SecurityVulns.com: HP Network Node Manager remote console weak files permissions</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=125063027228539&amp;w=2" xml:lang="en">HPSBMA02448</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017609" xml:lang="en">1017609</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://securityvulns.com/news/HP/NNM/RC/WP.html" xml:lang="en">http://securityvulns.com/news/HP/NNM/RC/WP.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22475" xml:lang="en">22475</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0533" xml:lang="en">ADV-2007-0533</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32362" xml:lang="en">openview-nnm-directory-privilege-escalation(32362)</vuln:reference>
    </vuln:references>
    <vuln:summary>HP Network Node Manager (NNM) Remote Console 7.50, 7.51, and 7.53 assigns Everyone Full Control permission for the %PROGRAMFILES%\HP OpenView directory tree, which allows local users to gain privileges via a Trojan horse executable file or ActiveX component, or a modified bin\ovtrcsvc.exe for the HP Open View Shared Trace Service.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0820">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cedric:claire_portailphp:2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cedric:claire_portailphp:2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0820</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:26.203-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22381" xml:lang="en">22381</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28867" xml:lang="en">28867</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/42123" xml:lang="en">portailphp-index-file-include(42123)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple PHP remote file inclusion vulnerabilities in Cedric CLAIRE PortailPhp 2 allow remote attackers to execute arbitrary PHP code via a URL in the chemin parameter to (1) mod_news/index.php, (2) mod_news/goodies.php, or (3) mod_search/index.php.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0821">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cedric:claire_portailphp:2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cedric:claire_portailphp:2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0821</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:42:03.030-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22381" xml:lang="en">22381</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple directory traversal vulnerabilities in Cedric CLAIRE PortailPhp 2 allow remote attackers to read arbitrary files via a .. (dot dot) in the chemin parameter to (1) mod_news/index.php or (2) mod_news/goodies.php.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0822">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0822</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-09-15T01:43:51.543-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>1.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0012.html" xml:lang="en">20070201 umount crash and xterm (kind of) information leak!</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://gotfault.wordpress.com/2007/01/18/umount-bug/" xml:lang="en">http://gotfault.wordpress.com/2007/01/18/umount-bug/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:053" xml:lang="en">MDKSA-2007:053</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22850" xml:lang="en">22850</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017729" xml:lang="en">1017729</vuln:reference>
    </vuln:references>
    <vuln:summary>umount, when running with the Linux 2.6.15 kernel on Slackware Linux 10.2, allows local users to trigger a NULL dereference and application crash by invoking the program with a pathname for a USB pen drive that was mounted and then physically removed, which might allow the users to obtain sensitive information, including core file contents.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0823">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:10.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:slackware:slackware_linux:10.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0823</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:42:03.453-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>1.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0012.html" xml:lang="en">20070201 umount crash and xterm (kind of) information leak!</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://gotfault.wordpress.com/2007/02/01/a-funny-case/" xml:lang="en">http://gotfault.wordpress.com/2007/02/01/a-funny-case/</vuln:reference>
    </vuln:references>
    <vuln:summary>xterm on Slackware Linux 10.2 stores information that had been displayed for a different user account using the same xterm process, which might allow local users to bypass file permissions and read other users' files, or obtain other sensitive information, by reading the xterm process memory.  NOTE: it could be argued that this is an expected consequence of multiple users sharing the same interactive process, in which case this is not a vulnerability.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0824">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:lightro:lightro_cms:1_beta"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:lightro:lightro_cms:1_beta</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0824</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:05.363-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22430" xml:lang="en">22430</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0511" xml:lang="en">ADV-2007-0511</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32270" xml:lang="en">lightro-inhalt-file-include(32270)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3275" xml:lang="en">3275</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in inhalt.php in LightRO CMS 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the dateien[news] parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0825">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:flashfxp:flashfxp:3.4.0_build_1145"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:flashfxp:flashfxp:3.4.0_build_1145</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0825</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:05.427-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22433" xml:lang="en">22433</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32416" xml:lang="en">flashfxp-pwdcommand-dos(32416)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3276" xml:lang="en">3276</vuln:reference>
    </vuln:references>
    <vuln:summary>FlashFXP 3.4.0 build 1145 allows remote servers to cause a denial of service (CPU consumption) via a response to a PWD command that contains a long string with deeply nested directory structure, possibly due to a buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0826">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:kisisel_site_2007:kisisel_site_forum.asp"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kisisel_site_2007:kisisel_site_forum.asp</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0826</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:05.473-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22435" xml:lang="en">22435</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0510" xml:lang="en">ADV-2007-0510</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32422" xml:lang="en">kisisel-forum-sql-injection(32422)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3278" xml:lang="en">3278</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in forum.asp in Kisisel Site 2007 allows remote attackers to execute arbitrary SQL commands via the forumid parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0827">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:alibaba:alipay_activex_control:2.4.2.471"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:alibaba:alipay_activex_control:2.4.2.471</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0827</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:05.537-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052250.html" xml:lang="en">20070207 Alibaba Alipay Remote Code Execute Vulnerability-0DAY</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22446" xml:lang="en">22446</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0520" xml:lang="en">ADV-2007-0520</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32367" xml:lang="en">alipay-activex-code-execution(32367)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3279" xml:lang="en">3279</vuln:reference>
    </vuln:references>
    <vuln:summary>The Alibaba Alipay PTA Module ActiveX control (PTA.DLL) allows remote attackers to execute arbitrary code via a JavaScript function that invokes the Remove method with an invalid index argument, which is used as an offset for a function call.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0828">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mysqlnewsengine:mysqlnewsengine"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mysqlnewsengine:mysqlnewsengine</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0828</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:52.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2229" xml:lang="en">2229</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459290/100/0/threaded" xml:lang="en">20070206 MySQLNewsEngine (affichearticles.php3) Remote File Inc. Vuln.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22431" xml:lang="en">22431</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0513" xml:lang="en">ADV-2007-0513</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32266" xml:lang="en">mysqlnewsengine-affichearticle-file-include(32266)</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in affichearticles.php3 in MySQLNewsEngine allows remote attackers to execute arbitrary PHP code via a URL in the newsenginedir parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0829">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:alwil:avast_antivirus:4.6.460::server"/>
        <cpe-lang:fact-ref name="cpe:/a:alwil:avast_antivirus:4.6.489::server"/>
        <cpe-lang:fact-ref name="cpe:/a:alwil:avast_antivirus:4.6.566::server"/>
        <cpe-lang:fact-ref name="cpe:/a:alwil:avast_antivirus:4.7.660::server"/>
        <cpe-lang:fact-ref name="cpe:/a:alwil:avast_antivirus:4.7.676::server"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:alwil:avast_antivirus:4.6.460::server</vuln:product>
      <vuln:product>cpe:/a:alwil:avast_antivirus:4.6.489::server</vuln:product>
      <vuln:product>cpe:/a:alwil:avast_antivirus:4.6.566::server</vuln:product>
      <vuln:product>cpe:/a:alwil:avast_antivirus:4.7.660::server</vuln:product>
      <vuln:product>cpe:/a:alwil:avast_antivirus:4.7.676::server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0829</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:26.517-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.4</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.avast.com/eng/avast-4-server-revision-history.html" xml:lang="en">http://www.avast.com/eng/avast-4-server-revision-history.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22425" xml:lang="en">22425</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0499" xml:lang="en">ADV-2007-0499</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32269" xml:lang="en">avast-password-security-bypass(32269)</vuln:reference>
    </vuln:references>
    <vuln:summary>avast! Server Edition before 4.7.726 does not demand a password in a certain intended context, even when a password has been set, which allows local users to bypass authentication requirements.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0830">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:3.6.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:jelsoft:vbulletin:3.6.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0830</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:53.060-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459289/100/0/threaded" xml:lang="en">20070206 VBulletin AdminCP Index.PHP Multiple Cross-Site Scripting Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459367/100/0/threaded" xml:lang="en">20070207 Re: VBulletin AdminCP Index.PHP Multiple Cross-Site Scripting Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32268" xml:lang="en">vbulletin-admincp-index-xss(32268)</vuln:reference>
    </vuln:references>
    <vuln:summary>** DISPUTED **  Multiple cross-site scripting (XSS) vulnerabilities in the Admin Control Panel (AdminCP) in Jelsoft vBulletin 3.6.4 allow remote authenticated administrators to inject arbitrary web script or HTML via unspecified vectors related to the (1) User Group Manager, (2) User Rank Manager, (3) User Title Manager, (4) BB Code Manager, (5) Attachment Manager, (6) Calendar Manager, and (7) Forums &amp; Moderators functions.  NOTE: the vendor disputes this issue, stating that modifying HTML is an intended privilege of an administrator.  NOTE: it is possible that this issue overlaps CVE-2006-6040.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0831">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:atsphp:atsphp:5.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:atsphp:atsphp:5.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0831</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:53.343-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458581/100/100/threaded" xml:lang="en">20070130 Atsphp 5.0.1 [Top Sites] [index.php] - Remote File Include</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458600/100/0/threaded" xml:lang="en">20070130 Re: BOGUS: Atsphp 5.0.1 [Top Sites] [index.php] - Remote File Include</vuln:reference>
    </vuln:references>
    <vuln:summary>** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in Atsphp 5.0.1 allow remote attackers to execute arbitrary PHP code via a URL in the CONF[path] parameter to (1) index.php, (2) sources/usercp.php, or (3) sources/admin.php.  NOTE: Another researcher has disputed this vulnerability, noting that CONF[path] is defined before use in index.php, that CONF[path] inclusion cannot occur through a direct request to other affected files, and that usercp.php is a typo of user_cp.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0832">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.3_build_34685"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vmware:workstation:5.5.3_build_34685</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0832</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:53.467-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>1.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459140/100/0/threaded" xml:lang="en">20070203 Vmare workstation guest isolation weaknesses (clipboard transfer)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22413" xml:lang="en">22413</vuln:reference>
    </vuln:references>
    <vuln:summary>VMware Workstation 5.5.3 34685 does not immediately change the availability of a shared clipboard when the "Enable copy and paste to and from this virtual machine" checkbox is changed, which allows local users to obtain sensitive information or conduct certain attacks that are facilitated by weaker isolation between the host and guest operating systems.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0833">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.3_build_34685"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vmware:workstation:5.5.3_build_34685</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0833</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:53.607-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>1.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459140/100/0/threaded" xml:lang="en">20070203 Vmare workstation guest isolation weaknesses (clipboard transfer)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22413" xml:lang="en">22413</vuln:reference>
    </vuln:references>
    <vuln:summary>VMware Workstation 5.5.3 34685, when the "Enable copy and paste to and from this virtual machine" option is enabled, preserves clipboard data on the guest operating system after it was deleted on the host operating system, which might allow local users to read clipboard contents by moving the focus back to the host operating system.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0834">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:darrens_5-dollar_script_archive:flashchat:4.7.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:darrens_5-dollar_script_archive:flashchat:4.7.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0834</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:26.627-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32417" xml:lang="en">flashchat-username-xss(32417)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in FlashChat 4.7.8 allows remote attackers to inject arbitrary web script or HTML via the user name field when the user joins a chat room, a different vulnerability than CVE-2007-0807.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0835">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:coppermine:coppermine_photo_gallery:1.4.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:coppermine:coppermine_photo_gallery:1.4.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0835</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:26.673-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22406" xml:lang="en">22406</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32236" xml:lang="en">coppermine-admin-command-execution(32236)</vuln:reference>
    </vuln:references>
    <vuln:summary>admin.php in Coppermine Photo Gallery 1.4.10, and possibly earlier, allows remote authenticated users to execute arbitrary shell commands via shell metacharacters (";" semicolon) in the "Command line options for ImageMagick" form field, when used as an option to ImageMagick's convert command.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0836">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:coppermine:coppermine_photo_gallery:1.4.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:coppermine:coppermine_photo_gallery:1.4.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0836</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:26.720-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22409" xml:lang="en">22409</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32233" xml:lang="en">coppermine-admin-file-include(32233)</vuln:reference>
    </vuln:references>
    <vuln:summary>admin.php in Coppermine Photo Gallery 1.4.10, and possibly earlier, allows remote authenticated users to include arbitrary local and possibly remote files via the (1) "Path to custom header include" and (2) "Path to custom footer include" form fields.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0837">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:agermenu:agermenu:0.03"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:agermenu:agermenu:0.03</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0837</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:05.583-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-February/001288.html" xml:lang="en">20070207 true: agermenu</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-February/001297.html" xml:lang="en">20070207 false: Agermenu 0.03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22442" xml:lang="en">22442</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0512" xml:lang="en">ADV-2007-0512</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32283" xml:lang="en">agermenu-topinc-file-include(32283)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3280" xml:lang="en">3280</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in examples/inc/top.inc.php in AgerMenu 0.03 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the rootdir parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0838">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:freeproxy:freeproxy:3.92"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:freeproxy:freeproxy:3.92</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0838</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:26.813-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=117086856902907&amp;w=2" xml:lang="en">20070206 Medium level security hole in FreeProxy</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://marc.info/?l=full-disclosure&amp;m=117085666921871&amp;w=2" xml:lang="en">20070206 Medium level security hole in FreeProxy</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.handcraftedsoftware.org/index.php?page=3&amp;mode=article&amp;k=60" xml:lang="en">http://www.handcraftedsoftware.org/index.php?page=3&amp;mode=article&amp;k=60</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22445" xml:lang="en">22445</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0514" xml:lang="en">ADV-2007-0514</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32303" xml:lang="en">freeproxy-hostname-portnumber-dos(32303)</vuln:reference>
    </vuln:references>
    <vuln:summary>FreeProxy before 3.92 Build 1626 allows malicious users to cause a denial of service (infinite loop) via a HOST: header with a hostname and port number that refers to the server itself.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0839">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:valarsoft:webmatic:2.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:valarsoft:webmatic:2.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0839</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:05.627-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-February/001292.html" xml:lang="en">20070207 true: WebMatic 2.6 RFI</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22444" xml:lang="en">22444</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0534" xml:lang="en">ADV-2007-0534</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32318" xml:lang="en">webmatic-indexalbum-file-include(32318)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3281" xml:lang="en">3281</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple PHP remote file inclusion vulnerabilities in index/index_album.php in Valarsoft WebMatic 2.6 allow remote attackers to execute arbitrary PHP code via a URL in the (1) P_LIB and (2) P_INDEX parameters.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0840">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:hlstats:hlstats:1.34"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hlstats:hlstats:1.34</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0840</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:42:06.907-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=484226" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=484226</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22422" xml:lang="en">22422</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in HLstats before 1.35 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in the search class.  NOTE: it is possible that this issue overlaps CVE-2006-4543.3 or CVE-2006-4454.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0841">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:vbdrupal:vbdrupal:4.7.5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vbdrupal:vbdrupal:4.7.5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0841</vuln:cve-id>
    <vuln:published-datetime>2007-02-07T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:50:49.487-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vbdrupal.org/forum/showthread.php?t=786" xml:lang="en">http://www.vbdrupal.org/forum/showthread.php?t=786</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0415" xml:lang="en">ADV-2007-0415</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple unspecified vulnerabilities in vbDrupal before 4.7.6.0 have unknown impact and remote attack vectors.  NOTE: the vector related to Drupal is covered by CVE-2007-0626.  These vulnerabilities might be associated with other CVE identifiers.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0842">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visual_c%2b%2b:8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visual_studio:2005"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:visual_c%2b%2b:8.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:visual_studio:2005</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0842</vuln:cve-id>
    <vuln:published-datetime>2007-02-13T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:53.747-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://msdn2.microsoft.com/en-us/library/a442x3ye(VS.80).aspx" xml:lang="en">http://msdn2.microsoft.com/en-us/library/a442x3ye(VS.80).aspx</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2237" xml:lang="en">2237</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459847/100/0/threaded" xml:lang="en">20070212 SecurityVulns.com: Microsoft Visual C++ 8.0 standard library time functions invalid assertion DoS (Problem 3000).</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32454" xml:lang="en">visualstudio-time-dos(32454)</vuln:reference>
    </vuln:references>
    <vuln:summary>The 64-bit versions of Microsoft Visual C++ 8.0 standard library (MSVCR80.DLL) time functions, including (1) localtime, (2) localtime_s, (3) gmtime, (4) gmtime_s, (5) ctime, (6) ctime_s, (7) wctime, (8) wctime_s, and (9) fstat, trigger an assertion error instead of a NULL pointer or EINVAL when processing a time argument later than Jan 1, 3000, which might allow context-dependent attackers to cause a denial of service (application exit) via large time values. NOTE: it could be argued that this is a design limitation of the functions, and the vulnerability lies with any application that does not validate arguments to these functions.  However, this behavior is inconsistent with documentation, which does not list assertions as a possible result of an error condition.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0843">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::beta1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp:::home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:64-bit_2003"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:embedded"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp1:tablet_pc"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:home"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:media_center"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:tablet_pc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::beta1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp:::home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:64-bit_2003</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:embedded</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp1:tablet_pc</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:home</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:media_center</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:professional</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:tablet_pc</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0843</vuln:cve-id>
    <vuln:published-datetime>2007-02-22T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:54.093-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052613.html" xml:lang="en">20070222 Microsoft Windows 2000/XP/2003/Vista ReadDirectoryChangesW informaton leak</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2282" xml:lang="en">2282</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://securityvulns.com/advisories/readdirectorychanges.asp" xml:lang="en">http://securityvulns.com/advisories/readdirectorychanges.asp</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460887/100/0/threaded" xml:lang="en">20070222 Re[2]: [Full-disclosure] Microsoft Windows 2000/XP/2003/Vista ReadDirectoryChangesW informaton leak</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460899/100/0/threaded" xml:lang="en">20070222 Microsoft Windows 2000/XP/2003/Vista ReadDirectoryChangesW informaton leak</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22664" xml:lang="en">22664</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0701" xml:lang="en">ADV-2007-0701</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32644" xml:lang="en">win-readdirectory-information-disclosure(32644)</vuln:reference>
    </vuln:references>
    <vuln:summary>The ReadDirectoryChangesW API function on Microsoft Windows 2000, XP, Server 2003, and Vista does not check permissions for child objects, which allows local users to bypass permissions by opening a directory with LIST (READ) access and using ReadDirectoryChangesW to monitor changes of files that do not have LIST permissions, which can be leveraged to determine filenames, access times, and other sensitive information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0844">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:pam_ssh:pam_ssh:1.91"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:pam_ssh:pam_ssh:1.91</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0844</vuln:cve-id>
    <vuln:published-datetime>2007-02-08T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:50:49.923-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=484376" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=484376</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22461" xml:lang="en">22461</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0524" xml:lang="en">ADV-2007-0524</vuln:reference>
    </vuln:references>
    <vuln:summary>The auth_via_key function in pam_ssh.c in pam_ssh before 1.92, when the allow_blank_passphrase option is disabled, allows remote attackers to bypass authentication restrictions and use private encryption keys requiring a blank passphrase by entering a non-blank passphrase.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0845">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:advanced_poll:advanced_poll:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:advanced_poll:advanced_poll:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:advanced_poll:advanced_poll:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:advanced_poll:advanced_poll:2.0.5::dev"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:advanced_poll:advanced_poll:2.0.2</vuln:product>
      <vuln:product>cpe:/a:advanced_poll:advanced_poll:2.0.3</vuln:product>
      <vuln:product>cpe:/a:advanced_poll:advanced_poll:2.0.4</vuln:product>
      <vuln:product>cpe:/a:advanced_poll:advanced_poll:2.0.5::dev</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0845</vuln:cve-id>
    <vuln:published-datetime>2007-02-08T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:05.677-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22451" xml:lang="en">22451</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32337" xml:lang="en">advancedpoll-uid-authentication-bypass(32337)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3282" xml:lang="en">3282</vuln:reference>
    </vuln:references>
    <vuln:summary>admin/index.php in Advanced Poll 2.0.0 through 2.0.5-dev allows remote attackers to bypass authentication and gain administrator privileges by obtaining a valid session identifier and setting the uid parameter to 1.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0846">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:open_tibia_server_cms:open_tibia_server_cms:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:open_tibia_server_cms:open_tibia_server_cms:2.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:open_tibia_server_cms:open_tibia_server_cms:2.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:open_tibia_server_cms:open_tibia_server_cms:2.1.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:open_tibia_server_cms:open_tibia_server_cms:2.0</vuln:product>
      <vuln:product>cpe:/a:open_tibia_server_cms:open_tibia_server_cms:2.1.3</vuln:product>
      <vuln:product>cpe:/a:open_tibia_server_cms:open_tibia_server_cms:2.1.4</vuln:product>
      <vuln:product>cpe:/a:open_tibia_server_cms:open_tibia_server_cms:2.1.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0846</vuln:cve-id>
    <vuln:published-datetime>2007-02-08T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:05.723-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22450" xml:lang="en">22450</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32324" xml:lang="en">otscms-forum-xss(32324)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3283" xml:lang="en">3283</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in forum.php in Open Tibia Server CMS (OTSCMS) 2.1.5 and earlier allows remote attackers to inject arbitrary HTML or web script via the name parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0847">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:open_tibia_server_cms:open_tibia_server_cms:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:open_tibia_server_cms:open_tibia_server_cms:2.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:open_tibia_server_cms:open_tibia_server_cms:2.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:open_tibia_server_cms:open_tibia_server_cms:2.1.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:open_tibia_server_cms:open_tibia_server_cms:2.0</vuln:product>
      <vuln:product>cpe:/a:open_tibia_server_cms:open_tibia_server_cms:2.1.3</vuln:product>
      <vuln:product>cpe:/a:open_tibia_server_cms:open_tibia_server_cms:2.1.4</vuln:product>
      <vuln:product>cpe:/a:open_tibia_server_cms:open_tibia_server_cms:2.1.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0847</vuln:cve-id>
    <vuln:published-datetime>2007-02-08T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:05.787-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22450" xml:lang="en">22450</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32322" xml:lang="en">otscms-priv-sql-injection(32322)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3283" xml:lang="en">3283</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in mod/PM/reply.php in Open Tibia Server CMS (OTSCMS) 2.1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to priv.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0848">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:maian_recipe:maian_recipe:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:maian_recipe:maian_recipe:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0848</vuln:cve-id>
    <vuln:published-datetime>2007-02-08T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:05.833-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-February/001299.html" xml:lang="en">20070207 true: Agermenu 0.03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0537" xml:lang="en">ADV-2007-0537</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32346" xml:lang="en">maianrecipe-classmail-file-include(32346)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3284" xml:lang="en">3284</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in classes/class_mail.inc.php in Maian Recipe 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_folder parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0849">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:syscp_team:syscp:1.2.15"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:syscp_team:syscp:1.2.15</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0849</vuln:cve-id>
    <vuln:published-datetime>2007-02-08T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:54.717-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459397/100/0/threaded" xml:lang="en">20070207 Ability to inject and execute any code as root in SysCP</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22453" xml:lang="en">22453</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.syscp.org/wiki/Security/SyscpOrgAbilityToInjectAndExecuteAnyCodeAsRootInSysCP" xml:lang="en">http://www.syscp.org/wiki/Security/SyscpOrgAbilityToInjectAndExecuteAnyCodeAsRootInSysCP</vuln:reference>
    </vuln:references>
    <vuln:summary>scripts/cronscript.php in SysCP 1.2.15 and earlier does not properly quote pathnames in user home directories, which allows local users to gain privileges by placing shell metacharacters in a directory name, and then using the control panel to protect this directory, a different vulnerability than CVE-2005-2568.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0850">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:syscp_team:syscp:1.2.10"/>
        <cpe-lang:fact-ref name="cpe:/a:syscp_team:syscp:1.2.15"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:syscp_team:syscp:1.2.10</vuln:product>
      <vuln:product>cpe:/a:syscp_team:syscp:1.2.15</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0850</vuln:cve-id>
    <vuln:published-datetime>2007-02-08T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:54.937-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459397/100/0/threaded" xml:lang="en">20070207 Ability to inject and execute any code as root in SysCP</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22454" xml:lang="en">22454</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.syscp.org/wiki/Security/SyscpOrgAbilityToInjectAndExecuteAnyCodeAsRootInSysCP" xml:lang="en">http://www.syscp.org/wiki/Security/SyscpOrgAbilityToInjectAndExecuteAnyCodeAsRootInSysCP</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32330" xml:lang="en">syscp-cronscript-code-execution(32330)</vuln:reference>
    </vuln:references>
    <vuln:summary>scripts/cronscript.php in SysCP 1.2.15 and earlier includes and executes arbitrary PHP scripts that are referenced by the panel_cronscript table in the SysCP database, which allows attackers with database write privileges to execute arbitrary code by constructing a PHP file and adding its filename to this table.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0851">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:client-server-messaging_suite_smb:gold::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:client-server_suite_smb:gold::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:control_manager:2.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:control_manager:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:control_manager:gold::as_400"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:control_manager:gold::s_390"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:control_manager:gold::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:control_manager:gold::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:control_manager:gold::windows_nt"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:control_manager:netware"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_emanager:3.5::hp"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_emanager:3.5.2::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_emanager:3.6::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_emanager:3.6::sun"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_emanager:3.51"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_emanager:3.51_j"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_messaging_security_suite:::linux_5.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_messaging_security_suite:3.81"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_messaging_security_suite:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_messaging_security_suite:5.5_build_1183"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_messaging_security_suite:gold::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_messaging_security_suite:gold::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_messaging_security_suite:gold::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_viruswall:3.0.1::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_viruswall:3.0.1::unix"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_viruswall:3.1.0::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_viruswall:3.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_viruswall:3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_viruswall:3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_viruswall:3.6::hp_ux"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_viruswall:3.6::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_viruswall:3.6::windows_nt"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_viruswall:3.6.0_build1166"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_viruswall:3.6.0_build_1182"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_viruswall:3.6.5::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_viruswall:3.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_viruswall:3.7.0_build1190"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_viruswall:3.8.0_build1130"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_viruswall:3.32"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_viruswall:3.81::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_viruswall:5.1::windows_nt"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_viruswall:gold::aix"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_viruswall:gold::linux_for_smb"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_viruswall:gold::smb"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_viruswall:gold::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_viruswall:gold::windows_nt_for_smb"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_viruswall_for_windows_nt:3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_viruswall_for_windows_nt:3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_viruswall_for_windows_nt:3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_viruswall_for_windows_nt:3.51"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_viruswall_for_windows_nt:3.52"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_viruswall_for_windows_nt:3.52_build1466"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_viruswall_for_windows_nt:5.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_viruswall_scan_engine:7.510.0-1002"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_web_security_suite:::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_web_security_suite:::linux_1.0.0_ja"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_web_security_suite:gold::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_web_security_suite:gold::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_web_security_suite:gold::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_webmanager:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_webmanager:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_webmanager:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_webprotect:gold::isa"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:officescan:3.0::corporate"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:officescan:4.5.0::microsof_sbs"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:officescan:7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:officescan:corporate_3.0::windows_nt_server"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:officescan:corporate_3.1.1::windows_nt_server"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:officescan:corporate_3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:officescan:corporate_3.5::windows_nt_server"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:officescan:corporate_3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:officescan:corporate_3.11::windows_nt_server"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:officescan:corporate_3.13"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:officescan:corporate_3.13::windows_nt_server"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:officescan:corporate_3.54"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:officescan:corporate_5.02"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:officescan:corporate_5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:officescan:corporate_5.58"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:officescan:corporate_6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:officescan:corporate_7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:officescan:corporate_7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:pc-cillin:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:pc-cillin:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:pc-cillin:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:pc-cillin:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:pc-cillin:2005"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:pc-cillin:2006"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:pc-cillin_internet_security:14_14.00.1485"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:pc-cillin_internet_security:2005_12.0.0_0_build_1244"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:pc-cillin_internet_security:2006_14.10.0.1023"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:pc-cillin_internet_security:2007"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:pc_cillin_-_internet_security_2006"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:portalprotect:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:portalprotect:1.2::sharepoint"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:scanmail:1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:scanmail:2.6::domino"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:scanmail:2.51::domino"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:scanmail:3.8::microsoft_exchange"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:scanmail:3.81::microsoft_exchange"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:scanmail:6.1::microsoft_exchange"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:scanmail:gold::lotus_domino_on_aix"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:scanmail:gold::lotus_domino_on_as_400"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:scanmail:gold::lotus_domino_on_s_390"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:scanmail:gold::lotus_domino_on_solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:scanmail:gold::lotus_domino_on_windows"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:scanmail_emanager"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:scanning_engine:7.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:serverprotect:5.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:serverprotect:5.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:serverprotect:5.58"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:serverprotect:5.58::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:serverprotect:linux"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:serverprotect:linux_1.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:serverprotect:novell_netware"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:serverprotect:windows"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:viruswall:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:web_security_suite:1.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:webprotect:3.1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:trend_micro:client-server-messaging_suite_smb:gold::windows</vuln:product>
      <vuln:product>cpe:/a:trend_micro:client-server_suite_smb:gold::windows</vuln:product>
      <vuln:product>cpe:/a:trend_micro:control_manager:2.5.0</vuln:product>
      <vuln:product>cpe:/a:trend_micro:control_manager:3.5</vuln:product>
      <vuln:product>cpe:/a:trend_micro:control_manager:gold::as_400</vuln:product>
      <vuln:product>cpe:/a:trend_micro:control_manager:gold::s_390</vuln:product>
      <vuln:product>cpe:/a:trend_micro:control_manager:gold::solaris</vuln:product>
      <vuln:product>cpe:/a:trend_micro:control_manager:gold::windows</vuln:product>
      <vuln:product>cpe:/a:trend_micro:control_manager:gold::windows_nt</vuln:product>
      <vuln:product>cpe:/a:trend_micro:control_manager:netware</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_emanager:3.5::hp</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_emanager:3.5.2::windows</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_emanager:3.6::linux</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_emanager:3.6::sun</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_emanager:3.51</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_emanager:3.51_j</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_messaging_security_suite:::linux_5.1.1</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_messaging_security_suite:3.81</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_messaging_security_suite:5.5</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_messaging_security_suite:5.5_build_1183</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_messaging_security_suite:gold::linux</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_messaging_security_suite:gold::solaris</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_messaging_security_suite:gold::windows</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_viruswall:3.0.1::linux</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_viruswall:3.0.1::unix</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_viruswall:3.1.0::linux</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_viruswall:3.2.3</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_viruswall:3.3</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_viruswall:3.6</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_viruswall:3.6::hp_ux</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_viruswall:3.6::solaris</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_viruswall:3.6::windows_nt</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_viruswall:3.6.0_build1166</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_viruswall:3.6.0_build_1182</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_viruswall:3.6.5::linux</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_viruswall:3.7.0</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_viruswall:3.7.0_build1190</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_viruswall:3.8.0_build1130</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_viruswall:3.32</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_viruswall:3.81::linux</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_viruswall:5.1::windows_nt</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_viruswall:gold::aix</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_viruswall:gold::linux_for_smb</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_viruswall:gold::smb</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_viruswall:gold::windows</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_viruswall:gold::windows_nt_for_smb</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_viruswall_for_windows_nt:3.4</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_viruswall_for_windows_nt:3.5</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_viruswall_for_windows_nt:3.6</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_viruswall_for_windows_nt:3.51</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_viruswall_for_windows_nt:3.52</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_viruswall_for_windows_nt:3.52_build1466</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_viruswall_for_windows_nt:5.1.0</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_viruswall_scan_engine:7.510.0-1002</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_web_security_suite:::linux</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_web_security_suite:::linux_1.0.0_ja</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_web_security_suite:gold::linux</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_web_security_suite:gold::solaris</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_web_security_suite:gold::windows</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_webmanager:1.2</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_webmanager:2.0</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_webmanager:2.1</vuln:product>
      <vuln:product>cpe:/a:trend_micro:interscan_webprotect:gold::isa</vuln:product>
      <vuln:product>cpe:/a:trend_micro:officescan:3.0::corporate</vuln:product>
      <vuln:product>cpe:/a:trend_micro:officescan:4.5.0::microsof_sbs</vuln:product>
      <vuln:product>cpe:/a:trend_micro:officescan:7.3</vuln:product>
      <vuln:product>cpe:/a:trend_micro:officescan:corporate_3.0::windows_nt_server</vuln:product>
      <vuln:product>cpe:/a:trend_micro:officescan:corporate_3.1.1::windows_nt_server</vuln:product>
      <vuln:product>cpe:/a:trend_micro:officescan:corporate_3.5</vuln:product>
      <vuln:product>cpe:/a:trend_micro:officescan:corporate_3.5::windows_nt_server</vuln:product>
      <vuln:product>cpe:/a:trend_micro:officescan:corporate_3.11</vuln:product>
      <vuln:product>cpe:/a:trend_micro:officescan:corporate_3.11::windows_nt_server</vuln:product>
      <vuln:product>cpe:/a:trend_micro:officescan:corporate_3.13</vuln:product>
      <vuln:product>cpe:/a:trend_micro:officescan:corporate_3.13::windows_nt_server</vuln:product>
      <vuln:product>cpe:/a:trend_micro:officescan:corporate_3.54</vuln:product>
      <vuln:product>cpe:/a:trend_micro:officescan:corporate_5.02</vuln:product>
      <vuln:product>cpe:/a:trend_micro:officescan:corporate_5.5</vuln:product>
      <vuln:product>cpe:/a:trend_micro:officescan:corporate_5.58</vuln:product>
      <vuln:product>cpe:/a:trend_micro:officescan:corporate_6.5</vuln:product>
      <vuln:product>cpe:/a:trend_micro:officescan:corporate_7.0</vuln:product>
      <vuln:product>cpe:/a:trend_micro:officescan:corporate_7.3</vuln:product>
      <vuln:product>cpe:/a:trend_micro:pc-cillin:6.0</vuln:product>
      <vuln:product>cpe:/a:trend_micro:pc-cillin:2000</vuln:product>
      <vuln:product>cpe:/a:trend_micro:pc-cillin:2002</vuln:product>
      <vuln:product>cpe:/a:trend_micro:pc-cillin:2003</vuln:product>
      <vuln:product>cpe:/a:trend_micro:pc-cillin:2005</vuln:product>
      <vuln:product>cpe:/a:trend_micro:pc-cillin:2006</vuln:product>
      <vuln:product>cpe:/a:trend_micro:pc-cillin_internet_security:14_14.00.1485</vuln:product>
      <vuln:product>cpe:/a:trend_micro:pc-cillin_internet_security:2005_12.0.0_0_build_1244</vuln:product>
      <vuln:product>cpe:/a:trend_micro:pc-cillin_internet_security:2006_14.10.0.1023</vuln:product>
      <vuln:product>cpe:/a:trend_micro:pc-cillin_internet_security:2007</vuln:product>
      <vuln:product>cpe:/a:trend_micro:pc_cillin_-_internet_security_2006</vuln:product>
      <vuln:product>cpe:/a:trend_micro:portalprotect:1.0</vuln:product>
      <vuln:product>cpe:/a:trend_micro:portalprotect:1.2::sharepoint</vuln:product>
      <vuln:product>cpe:/a:trend_micro:scanmail:1.0.0</vuln:product>
      <vuln:product>cpe:/a:trend_micro:scanmail:2.6::domino</vuln:product>
      <vuln:product>cpe:/a:trend_micro:scanmail:2.51::domino</vuln:product>
      <vuln:product>cpe:/a:trend_micro:scanmail:3.8::microsoft_exchange</vuln:product>
      <vuln:product>cpe:/a:trend_micro:scanmail:3.81::microsoft_exchange</vuln:product>
      <vuln:product>cpe:/a:trend_micro:scanmail:6.1::microsoft_exchange</vuln:product>
      <vuln:product>cpe:/a:trend_micro:scanmail:gold::lotus_domino_on_aix</vuln:product>
      <vuln:product>cpe:/a:trend_micro:scanmail:gold::lotus_domino_on_as_400</vuln:product>
      <vuln:product>cpe:/a:trend_micro:scanmail:gold::lotus_domino_on_s_390</vuln:product>
      <vuln:product>cpe:/a:trend_micro:scanmail:gold::lotus_domino_on_solaris</vuln:product>
      <vuln:product>cpe:/a:trend_micro:scanmail:gold::lotus_domino_on_windows</vuln:product>
      <vuln:product>cpe:/a:trend_micro:scanmail_emanager</vuln:product>
      <vuln:product>cpe:/a:trend_micro:scanning_engine:7.1.0</vuln:product>
      <vuln:product>cpe:/a:trend_micro:serverprotect:5.3.1</vuln:product>
      <vuln:product>cpe:/a:trend_micro:serverprotect:5.5.8</vuln:product>
      <vuln:product>cpe:/a:trend_micro:serverprotect:5.58</vuln:product>
      <vuln:product>cpe:/a:trend_micro:serverprotect:5.58::windows</vuln:product>
      <vuln:product>cpe:/a:trend_micro:serverprotect:linux</vuln:product>
      <vuln:product>cpe:/a:trend_micro:serverprotect:linux_1.2.0</vuln:product>
      <vuln:product>cpe:/a:trend_micro:serverprotect:novell_netware</vuln:product>
      <vuln:product>cpe:/a:trend_micro:serverprotect:windows</vuln:product>
      <vuln:product>cpe:/a:trend_micro:viruswall:3.0.1</vuln:product>
      <vuln:product>cpe:/a:trend_micro:web_security_suite:1.2.0</vuln:product>
      <vuln:product>cpe:/a:trend_micro:webprotect:3.1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0851</vuln:cve-id>
    <vuln:published-datetime>2007-02-08T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:27.360-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034289" xml:lang="en">http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034289</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>JVN</vuln:source>
      <vuln:reference href="http://jvn.jp/jp/JVN%2377366274/index.html" xml:lang="en">JVN#77366274</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=470" xml:lang="en">20070208 Trend Micro AntiVirus UPX Parsing Kernel Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017601" xml:lang="en">1017601</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017602" xml:lang="en">1017602</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017603" xml:lang="en">1017603</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.jpcert.or.jp/at/2007/at070004.txt" xml:lang="en">http://www.jpcert.or.jp/at/2007/at070004.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/276432" xml:lang="en">VU#276432</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22449" xml:lang="en">22449</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0522" xml:lang="en">ADV-2007-0522</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0569" xml:lang="en">ADV-2007-0569</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32352" xml:lang="en">antivirus-upx-bo(32352)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the Trend Micro Scan Engine 8.000 and 8.300 before virus pattern file 4.245.00, as used in other products such as Cyber Clean Center (CCC) Cleaner, allows remote attackers to execute arbitrary code via a malformed UPX compressed executable.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0852">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:techexcel_inc.:devtrack:6.0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:techexcel_inc.:devtrack:6.0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0852</vuln:cve-id>
    <vuln:published-datetime>2007-02-08T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:42:11.313-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22460" xml:lang="en">22460</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in DevTrack 6.x allows remote attackers to inject arbitrary web script or HTML via the "Keyword search" form field and unspecified other form fields that populate a public saved query.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0853">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:techexcel_inc.:devtrack:6.0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:techexcel_inc.:devtrack:6.0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0853</vuln:cve-id>
    <vuln:published-datetime>2007-02-08T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:27.407-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22460" xml:lang="en">22460</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32348" xml:lang="en">devtrack-username-sql-injection(32348)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in DevTrack 6.0.3 allows remote attackers to execute arbitrary SQL commands via the Username form field.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0854">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cpanel:webhost_manager"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cpanel:webhost_manager</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0854</vuln:cve-id>
    <vuln:published-datetime>2007-02-08T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:55.280-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://changelog.cpanel.net/index.cgi" xml:lang="en">http://changelog.cpanel.net/index.cgi</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459409/100/0/threaded" xml:lang="en">20070207 remote file include in whm (all version)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459449/100/0/threaded" xml:lang="en">20070208 Re: remote file include in whm (all version)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22455" xml:lang="en">22455</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0545" xml:lang="en">ADV-2007-0545</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32400" xml:lang="en">cpanel-webhost-objcache-xss(32400)</vuln:reference>
    </vuln:references>
    <vuln:summary>Remote file inclusion vulnerability in scripts2/objcache in cPanel WebHost Manager (WHM) allows remote attackers to execute arbitrary code via a URL in the obj parameter.  NOTE: a third party claims that this issue is not file inclusion because the contents are not parsed, but the attack can be used to overwrite files in /var/cpanel/objcache or provide unexpected web page contents.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0855">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:rarlab:unrar:3.60"/>
        <cpe-lang:fact-ref name="cpe:/a:rarlab:unrar:3.61"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rarlab:unrar:3.60</vuln:product>
      <vuln:product>cpe:/a:rarlab:unrar:3.61</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0855</vuln:cve-id>
    <vuln:published-datetime>2007-02-08T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:27.533-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=472" xml:lang="en">20070207 RARLabs Unrar Password Prompt Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200702-04.xml" xml:lang="en">GLSA-200702-04</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017593" xml:lang="en">1017593</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_5_sr.html" xml:lang="en">SUSE-SR:2007:005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22447" xml:lang="en">22447</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0523" xml:lang="en">ADV-2007-0523</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32357" xml:lang="en">unrar-password-archive-bo(32357)</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in RARLabs Unrar, as packaged in WinRAR and possibly other products, allows user-assisted remote attackers to execute arbitrary code via a crafted, password-protected archive.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0856">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:client-server-messaging_security:3.5::smb"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:damage_cleanup_services:3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:pc-cillin_internet_security:2007"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:tmcomm.sys:1.5.1052"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:trend_micro_antirootkit_common_module"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:trend_micro_antispyware:3.0_sp2::enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:trend_micro_antispyware:3.2_sp1::smb"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:trend_micro_antispyware:3.5::consumer"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:trend_micro_antivirus:2007"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:vsapini.sys:3.320.1003"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:trend_micro:client-server-messaging_security:3.5::smb</vuln:product>
      <vuln:product>cpe:/a:trend_micro:damage_cleanup_services:3.2</vuln:product>
      <vuln:product>cpe:/a:trend_micro:pc-cillin_internet_security:2007</vuln:product>
      <vuln:product>cpe:/a:trend_micro:tmcomm.sys:1.5.1052</vuln:product>
      <vuln:product>cpe:/a:trend_micro:trend_micro_antirootkit_common_module</vuln:product>
      <vuln:product>cpe:/a:trend_micro:trend_micro_antispyware:3.0_sp2::enterprise</vuln:product>
      <vuln:product>cpe:/a:trend_micro:trend_micro_antispyware:3.2_sp1::smb</vuln:product>
      <vuln:product>cpe:/a:trend_micro:trend_micro_antispyware:3.5::consumer</vuln:product>
      <vuln:product>cpe:/a:trend_micro:trend_micro_antivirus:2007</vuln:product>
      <vuln:product>cpe:/a:trend_micro:vsapini.sys:3.320.1003</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0856</vuln:cve-id>
    <vuln:published-datetime>2007-02-08T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:27.593-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034432&amp;id=EN-1034432" xml:lang="en">http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034432&amp;id=EN-1034432</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=469" xml:lang="en">20070207 Trend Micro TmComm Local Privilege Escalation Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017604" xml:lang="en">1017604</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017605" xml:lang="en">1017605</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017606" xml:lang="en">1017606</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/282240" xml:lang="en">VU#282240</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/666800" xml:lang="en">VU#666800</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22448" xml:lang="en">22448</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0521" xml:lang="en">ADV-2007-0521</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32353" xml:lang="en">trendmicro-tmcomm-privilege-escalation(32353)</vuln:reference>
    </vuln:references>
    <vuln:summary>TmComm.sys 1.5.0.1052 in the Trend Micro Anti-Rootkit Common Module (RCM), with the VsapiNI.sys 3.320.0.1003 scan engine, as used in Trend Micro PC-cillin Internet Security 2007, Antivirus 2007, Anti-Spyware for SMB 3.2 SP1, Anti-Spyware for Consumer 3.5, Anti-Spyware for Enterprise 3.0 SP2, Client / Server / Messaging Security for SMB 3.5, Damage Cleanup Services 3.2, and possibly other products, assigns Everyone write permission for the \\.\TmComm DOS device interface, which allows local users to access privileged IOCTLs and execute arbitrary code or overwrite arbitrary memory in the kernel context.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0857">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:moinmoin:moinmoin:1.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:moinmoin:moinmoin:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:moinmoin:moinmoin:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:moinmoin:moinmoin:1.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:moinmoin:moinmoin:1.5.3_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:moinmoin:moinmoin:1.5.3_rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:moinmoin:moinmoin:1.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:moinmoin:moinmoin:1.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:moinmoin:moinmoin:1.5.5_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:moinmoin:moinmoin:1.5.5a"/>
        <cpe-lang:fact-ref name="cpe:/a:moinmoin:moinmoin:1.5.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:moinmoin:moinmoin:1.5.0</vuln:product>
      <vuln:product>cpe:/a:moinmoin:moinmoin:1.5.1</vuln:product>
      <vuln:product>cpe:/a:moinmoin:moinmoin:1.5.2</vuln:product>
      <vuln:product>cpe:/a:moinmoin:moinmoin:1.5.3</vuln:product>
      <vuln:product>cpe:/a:moinmoin:moinmoin:1.5.3_rc1</vuln:product>
      <vuln:product>cpe:/a:moinmoin:moinmoin:1.5.3_rc2</vuln:product>
      <vuln:product>cpe:/a:moinmoin:moinmoin:1.5.4</vuln:product>
      <vuln:product>cpe:/a:moinmoin:moinmoin:1.5.5</vuln:product>
      <vuln:product>cpe:/a:moinmoin:moinmoin:1.5.5_rc1</vuln:product>
      <vuln:product>cpe:/a:moinmoin:moinmoin:1.5.5a</vuln:product>
      <vuln:product>cpe:/a:moinmoin:moinmoin:1.5.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0857</vuln:cve-id>
    <vuln:published-datetime>2007-02-08T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:27.657-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://moinmoin.wikiwikiweb.de/MoinMoinRelease1.5/CHANGES" xml:lang="en">http://moinmoin.wikiwikiweb.de/MoinMoinRelease1.5/CHANGES</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22506" xml:lang="en">22506</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-421-1" xml:lang="en">USN-421-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0553" xml:lang="en">ADV-2007-0553</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32377" xml:lang="en">moinmoin-pageinfo-pagename-xss(32377)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin before 1.5.7 allow remote attackers to inject arbitrary web script or HTML via (1) the page info, or the page name in a (2) AttachFile, (3) RenamePage, or (4) LocalSiteMap action.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0859">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:palm:treo:650"/>
        <cpe-lang:fact-ref name="cpe:/h:palm:treo:680"/>
        <cpe-lang:fact-ref name="cpe:/h:palm:treo:700p"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:palm:treo:650</vuln:product>
      <vuln:product>cpe:/h:palm:treo:680</vuln:product>
      <vuln:product>cpe:/h:palm:treo:700p</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0859</vuln:cve-id>
    <vuln:published-datetime>2007-02-15T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:55.797-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://discussion.treocentral.com/showthread.php?p=1199445&amp;posted=1#post1199445" xml:lang="en">http://discussion.treocentral.com/showthread.php?p=1199445&amp;posted=1#post1199445</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2260" xml:lang="en">2260</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460059/100/0/threaded" xml:lang="en">20070213 SYMSA-2007-002: Palm OS Treo Find Feature System Password Bypass</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460328/100/0/threaded" xml:lang="en">20070216 Re: SYMSA-2007-002: Palm OS Treo Find Feature System Password Bypass</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460901/100/0/threaded" xml:lang="en">20070222 SYMSA-2007-002-1: Palm OS Treo Find Feature System Password Bypass</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460908/100/0/threaded" xml:lang="en">20070222 Re: SYMSA-2007-002: Palm OS Treo Find Feature System Password Bypass</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460911/100/0/threaded" xml:lang="en">20070222 Re: Re: SYMSA-2007-002: Palm OS Treo Find Feature System Password Bypass</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460954/100/0/threaded" xml:lang="en">20070222 RE: SYMSA-2007-002: Palm OS Treo Find Feature System Password Bypass</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22468" xml:lang="en">22468</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.symantec.com/enterprise/research/SYMSA-2007-002.txt" xml:lang="en">http://www.symantec.com/enterprise/research/SYMSA-2007-002.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32502" xml:lang="en">palmos-findfeature-security-bypass(32502)</vuln:reference>
    </vuln:references>
    <vuln:summary>The Find feature in Palm OS Treo smart phones operates despite the system password lock, which allows attackers with physical access to obtain sensitive information (memory contents) by doing (1) text searches or (2) paste operations after pressing certain keyboard shortcut keys.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0860">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:laboratory_for_optical_and_computational_instrumentation:local_calendar_system:1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:laboratory_for_optical_and_computational_instrumentation:local_calendar_system:1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0860</vuln:cve-id>
    <vuln:published-datetime>2007-02-08T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:56.607-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458312/100/100/threaded" xml:lang="en">20070127 local Calendar System v1.1 (lcStdLib.inc) Remote File Include</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458457/100/100/threaded" xml:lang="en">20070128 Re: local Calendar System v1.1 (lcStdLib.inc) Remote File Include</vuln:reference>
    </vuln:references>
    <vuln:summary>** DISPUTED **  Multiple PHP remote file inclusion vulnerabilities in local Calendar System 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) TEMPLATE_DIR parameter to (a) showinvoices.php, (b) showmonth.php, (c) showevents.php, (d) retrieveinvoice.php, (e) modifyitem.php, and (f) lookup_userid.php; or the LIBDIR parameter to (g) editevent.php, (h) resetpassword.php, (i) signup.php, showmonth.php, (j) showday.php, showevents.php, and lookup_userid.php. NOTE: this issue has been disputed by a third party, who states that the associated variables are set in config.php before use.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0861">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpcoin:phpcoin:rc1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpcoin:phpcoin:rc1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0861</vuln:cve-id>
    <vuln:published-datetime>2007-02-08T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:56.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2230" xml:lang="en">2230</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458064/100/200/threaded" xml:lang="en">20070125 Re: phpCOIN &lt;= RC-1 (modules/mail/index.php) Remote File Include Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458080/100/200/threaded" xml:lang="en">20070125 phpCOIN &lt;= RC-1 (modules/mail/index.php) Remote File Include Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>** DISPUTED **  PHP remote file inclusion vulnerability in modules/mail/index.php in phpCOIN RC-1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _CCFG['_PKG_PATH_MDLS'] parameter.  NOTE: this issue has been disputed by a reliable third party, who states that a fatal error occurs before the relevant code is reached.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0862">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gnopaste:gnopaste:0.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:gnopaste:gnopaste:0.5.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnopaste:gnopaste:0.5.2</vuln:product>
      <vuln:product>cpe:/a:gnopaste:gnopaste:0.5.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0862</vuln:cve-id>
    <vuln:published-datetime>2007-02-08T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:56.997-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458460/100/100/threaded" xml:lang="en">20070129 gnopaste &lt;= 0.5.3 (index.php) Remote File Include Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/458559/100/100/threaded" xml:lang="en">20070129 Re: gnopaste &lt;= 0.5.3 (index.php) Remote File Include Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>** DISPUTED **  PHP remote file inclusion vulnerability in index.php in gnopaste 0.5.3 and earlier allows remote attackers to execute arbitrary PHP code via the GNP_REAL_PATH parameter.  NOTE: CVE and a third party dispute this issue, since GNP_REAL_PATH is a constant, not a variable.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0863">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:trevorchan:trevorchan:0.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:trevorchan:trevorchan:0.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0863</vuln:cve-id>
    <vuln:published-datetime>2007-02-08T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:42:13.937-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017512" xml:lang="en">1017512</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-January/001241.html" xml:lang="en">20070115 [Bogus] [ilkerkandemir at mynet.com: Trevorchan &lt;= v0.7 Remote File Include Vulnerability] (fwd)</vuln:reference>
    </vuln:references>
    <vuln:summary>** DISPUTED **  PHP remote file inclusion vulnerability in Trevorchan 0.7 and earlier allows remote attackers to execute arbitrary code via the tc_config[rootdir] parameter to (1) upgrade.php, (2) paint_save.php, (3) menu.php, (4) manage.php, and (5) banned.php.  NOTE: his issue has been disputed by reliable third parties, who state that the variable is set before use in config.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0864">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:lushiwarplaner:lushiwarplaner:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:lushiwarplaner:lushiwarplaner:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0864</vuln:cve-id>
    <vuln:published-datetime>2007-02-08T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:05.893-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22470" xml:lang="en">22470</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0538" xml:lang="en">ADV-2007-0538</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32365" xml:lang="en">lushiwarplaner-register-sql-injection(32365)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3288" xml:lang="en">3288</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in register.php in LushiWarPlaner 1.0 allows remote attackers to inject arbitrary SQL commands via the id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0865">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:lushinews:lushinews:1.00"/>
        <cpe-lang:fact-ref name="cpe:/a:lushinews:lushinews:1.01"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:lushinews:lushinews:1.00</vuln:product>
      <vuln:product>cpe:/a:lushinews:lushinews:1.01</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0865</vuln:cve-id>
    <vuln:published-datetime>2007-02-08T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:05.940-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22469" xml:lang="en">22469</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0539" xml:lang="en">ADV-2007-0539</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32360" xml:lang="en">lushinews-comments-sql-injection(32360)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3287" xml:lang="en">3287</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in comments.php in LushiNews 1.01 and earlier allows remote authenticated users to inject arbitrary SQL commands via the id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0866">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:hp:openview_storage_data_protector:5.50"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hp:openview_storage_data_protector:5.50</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0866</vuln:cve-id>
    <vuln:published-datetime>2007-02-08T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:57.153-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017614" xml:lang="en">1017614</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459497/100/0/threaded" xml:lang="en">HPSBMA02190</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22488" xml:lang="en">22488</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0542" xml:lang="en">ADV-2007-0542</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32386" xml:lang="en">openview-dataprotector-privilege-escalation(32386)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in HP OpenView Storage Data Protector on HP-UX B.11.00, B.11.11, or B.11.23 allows local users to execute arbitrary code via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0867">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:site-assistant:site-assistant:0990"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:site-assistant:site-assistant:0990</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0867</vuln:cve-id>
    <vuln:published-datetime>2007-02-09T14:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:05.987-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22467" xml:lang="en">22467</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0541" xml:lang="en">ADV-2007-0541</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32364" xml:lang="en">siteassistant-menu-file-include(32364)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3285" xml:lang="en">3285</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in classes/menu.php in Site-Assistant 0990 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the paths[version] parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0868">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:yahoo:messenger:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:yahoo:messenger:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:yahoo:messenger:5.0.1046"/>
        <cpe-lang:fact-ref name="cpe:/a:yahoo:messenger:5.0.1065"/>
        <cpe-lang:fact-ref name="cpe:/a:yahoo:messenger:5.0.1232"/>
        <cpe-lang:fact-ref name="cpe:/a:yahoo:messenger:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:yahoo:messenger:5.5.1249"/>
        <cpe-lang:fact-ref name="cpe:/a:yahoo:messenger:5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:yahoo:messenger:5.6.0.1347"/>
        <cpe-lang:fact-ref name="cpe:/a:yahoo:messenger:5.6.0.1351"/>
        <cpe-lang:fact-ref name="cpe:/a:yahoo:messenger:5.6.0.1355"/>
        <cpe-lang:fact-ref name="cpe:/a:yahoo:messenger:5.6.0.1356"/>
        <cpe-lang:fact-ref name="cpe:/a:yahoo:messenger:5.6.0.1358"/>
        <cpe-lang:fact-ref name="cpe:/a:yahoo:messenger:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:yahoo:messenger:6.0.0.1643"/>
        <cpe-lang:fact-ref name="cpe:/a:yahoo:messenger:6.0.0.1750"/>
        <cpe-lang:fact-ref name="cpe:/a:yahoo:messenger:6.0.0.1921"/>
        <cpe-lang:fact-ref name="cpe:/a:yahoo:messenger:7.0.438"/>
        <cpe-lang:fact-ref name="cpe:/a:yahoo:messenger:7.5.0.814"/>
        <cpe-lang:fact-ref name="cpe:/a:yahoo:messenger:8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:yahoo:messenger:8.0.0.863"/>
        <cpe-lang:fact-ref name="cpe:/a:yahoo:messenger:8.0_2005.1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:yahoo:messenger:8.1.0.209"/>
        <cpe-lang:fact-ref name="cpe:/a:yahoo:messenger:8.1.0.239"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:yahoo:messenger:4.0</vuln:product>
      <vuln:product>cpe:/a:yahoo:messenger:5.0</vuln:product>
      <vuln:product>cpe:/a:yahoo:messenger:5.0.1046</vuln:product>
      <vuln:product>cpe:/a:yahoo:messenger:5.0.1065</vuln:product>
      <vuln:product>cpe:/a:yahoo:messenger:5.0.1232</vuln:product>
      <vuln:product>cpe:/a:yahoo:messenger:5.5</vuln:product>
      <vuln:product>cpe:/a:yahoo:messenger:5.5.1249</vuln:product>
      <vuln:product>cpe:/a:yahoo:messenger:5.6</vuln:product>
      <vuln:product>cpe:/a:yahoo:messenger:5.6.0.1347</vuln:product>
      <vuln:product>cpe:/a:yahoo:messenger:5.6.0.1351</vuln:product>
      <vuln:product>cpe:/a:yahoo:messenger:5.6.0.1355</vuln:product>
      <vuln:product>cpe:/a:yahoo:messenger:5.6.0.1356</vuln:product>
      <vuln:product>cpe:/a:yahoo:messenger:5.6.0.1358</vuln:product>
      <vuln:product>cpe:/a:yahoo:messenger:6.0</vuln:product>
      <vuln:product>cpe:/a:yahoo:messenger:6.0.0.1643</vuln:product>
      <vuln:product>cpe:/a:yahoo:messenger:6.0.0.1750</vuln:product>
      <vuln:product>cpe:/a:yahoo:messenger:6.0.0.1921</vuln:product>
      <vuln:product>cpe:/a:yahoo:messenger:7.0.438</vuln:product>
      <vuln:product>cpe:/a:yahoo:messenger:7.5.0.814</vuln:product>
      <vuln:product>cpe:/a:yahoo:messenger:8.0</vuln:product>
      <vuln:product>cpe:/a:yahoo:messenger:8.0.0.863</vuln:product>
      <vuln:product>cpe:/a:yahoo:messenger:8.0_2005.1.1.4</vuln:product>
      <vuln:product>cpe:/a:yahoo:messenger:8.1.0.209</vuln:product>
      <vuln:product>cpe:/a:yahoo:messenger:8.1.0.239</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0868</vuln:cve-id>
    <vuln:published-datetime>2007-02-09T14:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:42:15.453-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22407" xml:lang="en">22407</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the Chat Room functionality in Yahoo! Messenger 8.1.0.239 and earlier allows remote attackers to cause a denial of service via unspecified vectors.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0869">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:3.6.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:jelsoft:vbulletin:3.6.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0869</vuln:cve-id>
    <vuln:published-datetime>2007-02-09T14:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:42:15.577-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22466" xml:lang="en">22466</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the Attachment Manager (admincp/attachment.php) in Jelsoft vBulletin 3.6.4 allows remote attackers to inject arbitrary web script or HTML via the Extension field.  NOTE: this might be a duplicate of CVE-2007-0830.5.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0870">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2000"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:word:2000</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0870</vuln:cve-id>
    <vuln:published-datetime>2007-02-11T16:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:57.513-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1860" name="oval:org.mitre.oval:def:1860"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0370.html" xml:lang="en">20070215 Word flaw CVE-2007-0870 confirmed as code execution type issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.avertlabs.com/research/blog/?p=199" xml:lang="en">http://www.avertlabs.com/research/blog/?p=199</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.avertlabs.com/research/blog/?p=206" xml:lang="en">http://www.avertlabs.com/research/blog/?p=206</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/332404" xml:lang="en">VU#332404</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/advisory/933052.mspx" xml:lang="en">http://www.microsoft.com/technet/security/advisory/933052.mspx</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/468871/100/200/threaded" xml:lang="en">HPSBST02214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22567" xml:lang="en">22567</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017653" xml:lang="en">1017653</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" xml:lang="en">TA07-128A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0607" xml:lang="en">ADV-2007-0607</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1709" xml:lang="en">ADV-2007-1709</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-024" xml:lang="en">MS07-024</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32503" xml:lang="en">word-document-string-code-execution(32503)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Microsoft Word 2000 allows remote attackers to cause a denial of service (crash) via unknown vectors, a different vulnerability than CVE-2006-5994, CVE-2006-6456, CVE-2006-6561, and CVE-2007-0515, a variant of Exploit-MS06-027.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0871">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:extremepow:extreme_file_hosting"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:extremepow:extreme_file_hosting</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0871</vuln:cve-id>
    <vuln:published-datetime>2007-02-12T14:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:58.450-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2231" xml:lang="en">2231</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459562/100/0/threaded" xml:lang="en">20070209 eXtreme File Hosting remote file upload vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22498" xml:lang="en">22498</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32435" xml:lang="en">extremefilehosting-compressed-file-upload(32435)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unrestricted file upload vulnerability in eXtremePow eXtreme File Hosting allows remote attackers to upload arbitrary PHP code via a filename with a double extension such as (1) .rar.php or (2) .zip.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0872">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:plain_old_webserver:plain_old_webserver:0.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:plain_old_webserver:plain_old_webserver:0.0.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:plain_old_webserver:plain_old_webserver:0.0.7</vuln:product>
      <vuln:product>cpe:/a:plain_old_webserver:plain_old_webserver:0.0.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0872</vuln:cve-id>
    <vuln:published-datetime>2007-02-12T14:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:28.437-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://seclists.org/fulldisclosure/2007/Feb/0196.html" xml:lang="en">20070209 Re: [WEB SECURITY] Plain Old Webserver - The coolest firefox extension</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://seclists.org/fulldisclosure/2007/Feb/0210.html" xml:lang="en">20070209 Re: [WEB SECURITY] Plain Old Webserver - The coolest firefox extension</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22502" xml:lang="en">22502</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0558" xml:lang="en">ADV-2007-0558</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://addons.mozilla.org/firefox/3002/" xml:lang="en">https://addons.mozilla.org/firefox/3002/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32467" xml:lang="en">pow-httprequest-directory-traversal(32467)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in the Plain Old Webserver (POW) add-on before 0.0.9 for Mozilla Firefox allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0873">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nabocorp:nabopoll:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:nabocorp:nabopoll:1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nabocorp:nabopoll:1.1</vuln:product>
      <vuln:product>cpe:/a:nabocorp:nabopoll:1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0873</vuln:cve-id>
    <vuln:published-datetime>2007-02-12T14:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:59.047-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://attrition.org/pipermail/vim/2007-February/001341.html" xml:lang="en">20070215 [milw0rm] exploit 3305</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://forums.avenir-geopolitique.net/viewtopic.php?t=2643" xml:lang="en">http://forums.avenir-geopolitique.net/viewtopic.php?t=2643</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2232" xml:lang="en">2232</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459655/100/0/threaded" xml:lang="en">20070210 nabopoll 1.1.2 sensitive file (admin without password)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22509" xml:lang="en">22509</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32472" xml:lang="en">nabopoll-adminscripts-unauthorized-access(32472)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3305" xml:lang="en">3305</vuln:reference>
    </vuln:references>
    <vuln:summary>nabopoll 1.1.2 allows remote attackers to bypass authentication and access certain administrative functionality via a direct request for (1) config_edit.php, (2) template_edit.php, or (3) survey_edit.php in admin/.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0874">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:allons_voter:allons_voter:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:allons_voter:allons_voter:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0874</vuln:cve-id>
    <vuln:published-datetime>2007-02-12T14:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:59.530-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://forums.avenir-geopolitique.net/viewtopic.php?t=2641" xml:lang="en">http://forums.avenir-geopolitique.net/viewtopic.php?t=2641</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2234" xml:lang="en">2234</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459652/100/0/threaded" xml:lang="en">20070209 Allons_voter Version 1.0 xss and admin votes</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22508" xml:lang="en">22508</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32431" xml:lang="en">allonsvoter-admin-authentication-bypass(32431)</vuln:reference>
    </vuln:references>
    <vuln:summary>Allons_voter 1.0 allows remote attackers to bypass authentication and access certain administrative functionality via a direct request for (1) admin_ajouter.php or (2) admin_supprimer.php.  NOTE: this could be leveraged to conduct cross-site scripting (XSS) attacks.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0875">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mcrefer:mcrefer:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mcrefer:mcrefer:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0875</vuln:cve-id>
    <vuln:published-datetime>2007-02-12T14:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:34:59.873-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://forums.avenir-geopolitique.net/viewtopic.php?t=2642" xml:lang="en">http://forums.avenir-geopolitique.net/viewtopic.php?t=2642</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2235" xml:lang="en">2235</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459649/100/0/threaded" xml:lang="en">20070209 mcRefer SQL injection</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459796/100/200/threaded" xml:lang="en">20070211 Re: mcRefer SQL injection</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22507" xml:lang="en">22507</vuln:reference>
    </vuln:references>
    <vuln:summary>** DISPUTED **  SQL injection vulnerability in install.php in mcRefer allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: this issue has been disputed by a third party, stating that the file does not use a SQL database.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0876">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:qdig:qdig:1.2.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:qdig:qdig:2006-06-24_dev"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:qdig:qdig:1.2.9.3</vuln:product>
      <vuln:product>cpe:/a:qdig:qdig:2006-06-24_dev</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0876</vuln:cve-id>
    <vuln:published-datetime>2007-02-12T14:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:00.200-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?group_id=69837&amp;release_id=485558" xml:lang="en">http://sourceforge.net/project/shownotes.php?group_id=69837&amp;release_id=485558</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459664/100/0/threaded" xml:lang="en">20070210 [XSS] Qdig - Quick Digital Image Gallery Version 1.2.9.3 and -devel</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459791/100/0/threaded" xml:lang="en">20070211 Re: [XSS] Qdig - Quick Digital Image Gallery Version 1.2.9.3 and -devel</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22510" xml:lang="en">22510</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0555" xml:lang="en">ADV-2007-0555</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32421" xml:lang="en">qdig-qwd-xss(32421)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Quick Digital Image Gallery (Qdig) 1.2.9.3 and devel-20060624 allows remote attackers to inject arbitrary web script or HTML via the Qwd parameter to the top-level URI.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0877">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:march_networks:3108_dvr"/>
        <cpe-lang:fact-ref name="cpe:/h:march_networks:3204_dvr"/>
        <cpe-lang:fact-ref name="cpe:/h:march_networks:4210_dvr"/>
        <cpe-lang:fact-ref name="cpe:/h:march_networks:4310_dvr"/>
        <cpe-lang:fact-ref name="cpe:/h:march_networks:4410_dvr"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:march_networks:3108_dvr</vuln:product>
      <vuln:product>cpe:/h:march_networks:3204_dvr</vuln:product>
      <vuln:product>cpe:/h:march_networks:4210_dvr</vuln:product>
      <vuln:product>cpe:/h:march_networks:4310_dvr</vuln:product>
      <vuln:product>cpe:/h:march_networks:4410_dvr</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0877</vuln:cve-id>
    <vuln:published-datetime>2007-02-12T14:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:42:17.907-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22497" xml:lang="en">22497</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in March Networks DVR 3000 and 4000 Digital Video Recorders allows attackers to cause an unspecified denial of service.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0878">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_mobile:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_mobile:5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0878</vuln:cve-id>
    <vuln:published-datetime>2007-02-12T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:10.717-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052293.html" xml:lang="en">20070209 Denial Of Service in Internet Explorer for MS Windows Mobile 5.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459571/100/0/threaded" xml:lang="en">20070209 Denial Of Service in Internet Explorer for MS Windows Mobile 5.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459584/100/0/threaded" xml:lang="en">20070209 Re: Denial Of Service in Internet Explorer for MS Windows Mobile 5.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459591/100/0/threaded" xml:lang="en">20070209 RE: Denial Of Service in Internet Explorer for MS Windows Mobile 5.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22500" xml:lang="en">22500</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32394" xml:lang="en">ie-mobile-wml-dos(32394)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Microsoft Internet Explorer on Windows Mobile 5.0 allows remote attackers to cause a denial of service (loss of browser and other device functionality) via a malformed WML page, related to an "overflow state." NOTE: it is possible that this issue is related to CVE-2007-0685.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0879">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:smidgeonsoft:pebrowse:professional_8.2.1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:smidgeonsoft:pebrowse:professional_8.2.1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0879</vuln:cve-id>
    <vuln:published-datetime>2007-02-12T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:28.687-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22501" xml:lang="en">22501</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0665" xml:lang="en">ADV-2007-0665</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32524" xml:lang="en">smidgeonsoft-files-bo(32524)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in SmidgeonSoft PEBrowse Professional 8.2.1.0 allows user-assisted remote attackers to execute arbitrary code via certain executable files in PE format.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0880">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:capital_request_forms:capital_request_forms"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:capital_request_forms:capital_request_forms</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0880</vuln:cve-id>
    <vuln:published-datetime>2007-02-12T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:02.153-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459574/100/0/threaded" xml:lang="en">20070209 Capital Request Forms Db Username and Password Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:summary>Capital Request Forms stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database credentials via a direct request for inc/common_db.inc.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0881">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:openi-cms_group:openi-cms:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openi-cms_group:openi-cms:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0881</vuln:cve-id>
    <vuln:published-datetime>2007-02-12T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:06.050-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://echo.or.id/adv/adv64-y3dips-2007.txt" xml:lang="en">http://echo.or.id/adv/adv64-y3dips-2007.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22511" xml:lang="en">22511</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0556" xml:lang="en">ADV-2007-0556</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32423" xml:lang="en">internalrange-oidir-file-include(32423)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3292" xml:lang="en">3292</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in the Seitenschutz plugin for OPENi-CMS 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the (1) config[oi_dir] and possibly (2) config[openi_dir] parameters to open-admin/plugins/site_protection/index.php.  NOTE: vector 2 might be the same as CVE-2006-4750.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0882">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:10.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:10.0::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.10"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:10.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:10.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.10</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0882</vuln:cve-id>
    <vuln:published-datetime>2007-02-12T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:11.920-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2202" name="oval:org.mitre.oval:def:2202"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://erratasec.blogspot.com/2007/02/trivial-remote-solaris-0day-disable.html" xml:lang="en">http://erratasec.blogspot.com/2007/02/trivial-remote-solaris-0day-disable.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://isc.sans.org/diary.html?storyid=2220" xml:lang="en">http://isc.sans.org/diary.html?storyid=2220</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://seclists.org/fulldisclosure/2007/Feb/0217.html" xml:lang="en">20070211 "0day was the case that they gave me"</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102802-1" xml:lang="en">102802</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/881872" xml:lang="en">VU#881872</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459831/100/0/threaded" xml:lang="en">20070212 Re: [Full-disclosure] Solaris telnet vulnberability - how many on your network?</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459843/100/0/threaded" xml:lang="en">20070212 Solaris telnet vulnberability - how many on your network?</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459855/100/0/threaded" xml:lang="en">20070212 Re: [BLACKLIST] [Full-disclosure] Solaris telnet vulnberability - how many on yournetwork?</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459980/100/0/threaded" xml:lang="en">20070213 Re: [BLACKLIST] [Full-disclosure] Solaris telnet vulnberability - how many on yournetwork?</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460086/100/100/threaded" xml:lang="en">20070214 Solaris telnet vuln solutions digest and network risks</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460103/100/100/threaded" xml:lang="en">20070214 RE: [Full-disclosure] Solaris telnet vulnberability - how many onyour network?</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22512" xml:lang="en">22512</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017625" xml:lang="en">1017625</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-059A.html" xml:lang="en">TA07-059A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0560" xml:lang="en">ADV-2007-0560</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32434" xml:lang="en">solaris-telnet-authentication-bypass(32434)</vuln:reference>
    </vuln:references>
    <vuln:summary>Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" sequences as valid requests for the login program to skip authentication, which allows remote attackers to log into certain accounts, as demonstrated by the bin account.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0883">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:second_rule_llc:ip3_netaccess:4.1.9.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:second_rule_llc:ip3_netaccess:4.1.9.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0883</vuln:cve-id>
    <vuln:published-datetime>2007-02-12T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:03.763-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0235.html" xml:lang="en">20070211 Arbitrary file disclosure vulnerability in IP3 NetAccess &lt; 4.1.9.6</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.devtarget.org/ip3-advisory-02-2007.txt" xml:lang="en">http://www.devtarget.org/ip3-advisory-02-2007.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459806/100/0/threaded" xml:lang="en">20070211 Arbitrary file disclosure vulnerability in IP3 NetAccess &lt; 4.1.9.6</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22513" xml:lang="en">22513</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017623" xml:lang="en">1017623</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0615" xml:lang="en">ADV-2007-0615</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32432" xml:lang="en">ip3netaccess-getfile-directory-traversal(32432)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3294" xml:lang="en">3294</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in portalgroups/portalgroups/getfile.cgi in IP3 NetAccess before firmware 4.1.9.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0884">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:roaring_penguin:mimedefang:2.59"/>
        <cpe-lang:fact-ref name="cpe:/a:roaring_penguin:mimedefang:2.60"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:roaring_penguin:mimedefang:2.59</vuln:product>
      <vuln:product>cpe:/a:roaring_penguin:mimedefang:2.60</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0884</vuln:cve-id>
    <vuln:published-datetime>2007-02-12T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:28.923-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.roaringpenguin.com/pipermail/mimedefang/2007-February/032011.html" xml:lang="en">[mimedefang] 20070209 SECURITY: MIMEDefang 2.61 is Released</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mimedefang.org/node.php?id=62" xml:lang="en">http://www.mimedefang.org/node.php?id=62</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22514" xml:lang="en">22514</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0572" xml:lang="en">ADV-2007-0572</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32466" xml:lang="en">mimedefang-unspecified-bo(32466)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Roaring Penguin MIMEDefang 2.59 and 2.60 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0885">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:rainbow_portal:rainbow.zen"/>
        <cpe-lang:fact-ref name="cpe:/a:rainbow_portal:rainbow_with_the_zen"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rainbow_portal:rainbow.zen</vuln:product>
      <vuln:product>cpe:/a:rainbow_portal:rainbow_with_the_zen</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0885</vuln:cve-id>
    <vuln:published-datetime>2007-02-12T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:04.357-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459590/100/0/threaded" xml:lang="en">20070209 XSS in Rainbow with Rainbow.Zen</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22503" xml:lang="en">22503</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32418" xml:lang="en">rainbow-browseproject-xss(32418)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in jira/secure/BrowseProject.jspa in Rainbow with the Zen (Rainbow.Zen) extension allows remote attackers to inject arbitrary web script or HTML via the id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0886">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gecad_technologies:axigen_mail_server:1.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:gecad_technologies:axigen_mail_server:2.0.0b1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gecad_technologies:axigen_mail_server:1.2.6</vuln:product>
      <vuln:product>cpe:/a:gecad_technologies:axigen_mail_server:2.0.0b1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0886</vuln:cve-id>
    <vuln:published-datetime>2007-02-12T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:06.160-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://marc.info/?l=full-disclosure&amp;m=117094708423302&amp;w=2" xml:lang="en">20070208 Axigen &lt;2.0.0b1 DoS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22473" xml:lang="en">22473</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32342" xml:lang="en">axigen-memcpy-dos(32342)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3289" xml:lang="en">3289</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer underflow in axigen 1.2.6 through 2.0.0b1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via certain base64-encoded data on the pop3 port (110/tcp), which triggers an integer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0887">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gecad_technologies:axigen_mail_server:1.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:gecad_technologies:axigen_mail_server:2.0.0b1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gecad_technologies:axigen_mail_server:1.2.6</vuln:product>
      <vuln:product>cpe:/a:gecad_technologies:axigen_mail_server:2.0.0b1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0887</vuln:cve-id>
    <vuln:published-datetime>2007-02-12T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:06.207-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-476"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://marc.info/?l=full-disclosure&amp;m=117094708423302&amp;w=2" xml:lang="en">20070208 Axigen &lt;2.0.0b1 DoS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22473" xml:lang="en">22473</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32345" xml:lang="en">axigen-nullpointer-dos(32345)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3290" xml:lang="en">3290</vuln:reference>
    </vuln:references>
    <vuln:summary>axigen 1.2.6 through 2.0.0b1 does not properly parse login credentials, which allows remote attackers to cause a denial of service (NULL dereference and application crash) via a base64-encoded "*\x00" sequence on the imap port (143/tcp).</vuln:summary>
  </entry>
  <entry id="CVE-2007-0888">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:kiwi_enterprises:kiwi_cattools"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kiwi_enterprises:kiwi_cattools</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0888</vuln:cve-id>
    <vuln:published-datetime>2007-02-12T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:04.560-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2236" xml:lang="en">2236</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kiwisyslog.com/kb/idx/5/178/article/" xml:lang="en">http://www.kiwisyslog.com/kb/idx/5/178/article/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459500/100/0/threaded" xml:lang="en">20070208 TFTP directory traversal in Kiwi CatTools</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459933/100/0/threaded" xml:lang="en">20070213 Re: TFTP directory traversal in Kiwi CatTools</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22490" xml:lang="en">22490</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0536" xml:lang="en">ADV-2007-0536</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32398" xml:lang="en">kiwicattools-tftp-directory-traversal(32398)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in the TFTP server in Kiwi CatTools before 3.2.0 beta allows remote attackers to read arbitrary files, and upload files to arbitrary locations, via ..// (dot dot) sequences in the pathname argument to an FTP (1) GET or (2) PUT command.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0889">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:kiwi_enterprises:kiwi_cattools"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kiwi_enterprises:kiwi_cattools</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0889</vuln:cve-id>
    <vuln:published-datetime>2007-02-12T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:05.013-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2236" xml:lang="en">2236</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459500/100/0/threaded" xml:lang="en">20070208 TFTP directory traversal in Kiwi CatTools</vuln:reference>
    </vuln:references>
    <vuln:summary>Kiwi CatTools before 3.2.0 beta uses weak encryption ("reversible encoding") for passwords, account names, and IP addresses in kiwidb-cattools.kdb, which might allow local users to gain sensitive information by decrypting the file.  NOTE: this issue could be leveraged with a directory traversal vulnerability for a remote attack vector.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0890">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cpanel:webhost_manager:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cpanel:webhost_manager:5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:cpanel:webhost_manager:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cpanel:webhost_manager:6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:cpanel:webhost_manager:6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:cpanel:webhost_manager:6.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cpanel:webhost_manager:6.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:cpanel:webhost_manager:6.4.2_stable_48"/>
        <cpe-lang:fact-ref name="cpe:/a:cpanel:webhost_manager:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cpanel:webhost_manager:8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cpanel:webhost_manager:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cpanel:webhost_manager:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cpanel:webhost_manager:9.1.0_r85"/>
        <cpe-lang:fact-ref name="cpe:/a:cpanel:webhost_manager:9.4.1_r64"/>
        <cpe-lang:fact-ref name="cpe:/a:cpanel:webhost_manager:9.9.1_r3"/>
        <cpe-lang:fact-ref name="cpe:/a:cpanel:webhost_manager:10.2.0_r82"/>
        <cpe-lang:fact-ref name="cpe:/a:cpanel:webhost_manager:10.6.0_r137"/>
        <cpe-lang:fact-ref name="cpe:/a:cpanel:webhost_manager:10.8.1_113"/>
        <cpe-lang:fact-ref name="cpe:/a:cpanel:webhost_manager:10.8.1_build84"/>
        <cpe-lang:fact-ref name="cpe:/a:cpanel:webhost_manager:10.8.2_118"/>
        <cpe-lang:fact-ref name="cpe:/a:cpanel:webhost_manager:10.9"/>
        <cpe-lang:fact-ref name="cpe:/a:cpanel:webhost_manager:11"/>
        <cpe-lang:fact-ref name="cpe:/a:cpanel:webhost_manager:11.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cpanel:webhost_manager:11_beta"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cpanel:webhost_manager:5.0</vuln:product>
      <vuln:product>cpe:/a:cpanel:webhost_manager:5.3</vuln:product>
      <vuln:product>cpe:/a:cpanel:webhost_manager:6.0</vuln:product>
      <vuln:product>cpe:/a:cpanel:webhost_manager:6.2</vuln:product>
      <vuln:product>cpe:/a:cpanel:webhost_manager:6.4</vuln:product>
      <vuln:product>cpe:/a:cpanel:webhost_manager:6.4.1</vuln:product>
      <vuln:product>cpe:/a:cpanel:webhost_manager:6.4.2</vuln:product>
      <vuln:product>cpe:/a:cpanel:webhost_manager:6.4.2_stable_48</vuln:product>
      <vuln:product>cpe:/a:cpanel:webhost_manager:7.0</vuln:product>
      <vuln:product>cpe:/a:cpanel:webhost_manager:8.0</vuln:product>
      <vuln:product>cpe:/a:cpanel:webhost_manager:9.0</vuln:product>
      <vuln:product>cpe:/a:cpanel:webhost_manager:9.1</vuln:product>
      <vuln:product>cpe:/a:cpanel:webhost_manager:9.1.0_r85</vuln:product>
      <vuln:product>cpe:/a:cpanel:webhost_manager:9.4.1_r64</vuln:product>
      <vuln:product>cpe:/a:cpanel:webhost_manager:9.9.1_r3</vuln:product>
      <vuln:product>cpe:/a:cpanel:webhost_manager:10.2.0_r82</vuln:product>
      <vuln:product>cpe:/a:cpanel:webhost_manager:10.6.0_r137</vuln:product>
      <vuln:product>cpe:/a:cpanel:webhost_manager:10.8.1_113</vuln:product>
      <vuln:product>cpe:/a:cpanel:webhost_manager:10.8.1_build84</vuln:product>
      <vuln:product>cpe:/a:cpanel:webhost_manager:10.8.2_118</vuln:product>
      <vuln:product>cpe:/a:cpanel:webhost_manager:10.9</vuln:product>
      <vuln:product>cpe:/a:cpanel:webhost_manager:11</vuln:product>
      <vuln:product>cpe:/a:cpanel:webhost_manager:11.0</vuln:product>
      <vuln:product>cpe:/a:cpanel:webhost_manager:11_beta</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0890</vuln:cve-id>
    <vuln:published-datetime>2007-02-12T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:05.187-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://changelog.cpanel.net/index.cgi" xml:lang="en">http://changelog.cpanel.net/index.cgi</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459585/100/0/threaded" xml:lang="en">20070208 local bug :[xxs] in whm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22474" xml:lang="en">22474</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0568" xml:lang="en">ADV-2007-0568</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in scripts/passwdmysql in cPanel WebHost Manager (WHM) 11.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the password parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0891">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:matthieu_aubry:phpmyvisites:0.1_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:matthieu_aubry:phpmyvisites:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:matthieu_aubry:phpmyvisites:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:matthieu_aubry:phpmyvisites:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:matthieu_aubry:phpmyvisites:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:matthieu_aubry:phpmyvisites:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:matthieu_aubry:phpmyvisites:1.2_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:matthieu_aubry:phpmyvisites:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:matthieu_aubry:phpmyvisites:2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:matthieu_aubry:phpmyvisites:0.1_beta</vuln:product>
      <vuln:product>cpe:/a:matthieu_aubry:phpmyvisites:1.0</vuln:product>
      <vuln:product>cpe:/a:matthieu_aubry:phpmyvisites:1.1</vuln:product>
      <vuln:product>cpe:/a:matthieu_aubry:phpmyvisites:1.2</vuln:product>
      <vuln:product>cpe:/a:matthieu_aubry:phpmyvisites:1.2.1</vuln:product>
      <vuln:product>cpe:/a:matthieu_aubry:phpmyvisites:1.2.2</vuln:product>
      <vuln:product>cpe:/a:matthieu_aubry:phpmyvisites:1.2_beta</vuln:product>
      <vuln:product>cpe:/a:matthieu_aubry:phpmyvisites:1.3</vuln:product>
      <vuln:product>cpe:/a:matthieu_aubry:phpmyvisites:2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0891</vuln:cve-id>
    <vuln:published-datetime>2007-02-12T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:05.467-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://marc.info/?l=full-disclosure&amp;m=117121596803908&amp;w=2" xml:lang="en">20070211 Multiple vulnerabilities in phpMyVisites</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459792/100/0/threaded" xml:lang="en">20070211 Multiple vulnerabilities in phpMyVisites</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22516" xml:lang="en">22516</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32430" xml:lang="en">phpmyvisites-phpmyvisites-xss(32430)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the GetCurrentCompletePath function in phpmyvisites.php in phpMyVisites before 2.2 allows remote attackers to inject arbitrary web script or HTML via the query string.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0892">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:matthieu_aubry:phpmyvisites:0.1_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:matthieu_aubry:phpmyvisites:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:matthieu_aubry:phpmyvisites:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:matthieu_aubry:phpmyvisites:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:matthieu_aubry:phpmyvisites:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:matthieu_aubry:phpmyvisites:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:matthieu_aubry:phpmyvisites:1.2_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:matthieu_aubry:phpmyvisites:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:matthieu_aubry:phpmyvisites:2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:matthieu_aubry:phpmyvisites:0.1_beta</vuln:product>
      <vuln:product>cpe:/a:matthieu_aubry:phpmyvisites:1.0</vuln:product>
      <vuln:product>cpe:/a:matthieu_aubry:phpmyvisites:1.1</vuln:product>
      <vuln:product>cpe:/a:matthieu_aubry:phpmyvisites:1.2</vuln:product>
      <vuln:product>cpe:/a:matthieu_aubry:phpmyvisites:1.2.1</vuln:product>
      <vuln:product>cpe:/a:matthieu_aubry:phpmyvisites:1.2.2</vuln:product>
      <vuln:product>cpe:/a:matthieu_aubry:phpmyvisites:1.2_beta</vuln:product>
      <vuln:product>cpe:/a:matthieu_aubry:phpmyvisites:1.3</vuln:product>
      <vuln:product>cpe:/a:matthieu_aubry:phpmyvisites:2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0892</vuln:cve-id>
    <vuln:published-datetime>2007-02-12T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:05.890-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-93"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://marc.info/?l=full-disclosure&amp;m=117121596803908&amp;w=2" xml:lang="en">20070211 Multiple vulnerabilities in phpMyVisites</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459792/100/0/threaded" xml:lang="en">20070211 Multiple vulnerabilities in phpMyVisites</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32428" xml:lang="en">phpmyvisites-pagename-response-splitting(32428)</vuln:reference>
    </vuln:references>
    <vuln:summary>CRLF injection vulnerability in phpMyVisites before 2.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the url parameter, when the pagename parameter begins with "FILE:".</vuln:summary>
  </entry>
  <entry id="CVE-2007-0893">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:matthieu_aubry:phpmyvisites:0.1_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:matthieu_aubry:phpmyvisites:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:matthieu_aubry:phpmyvisites:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:matthieu_aubry:phpmyvisites:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:matthieu_aubry:phpmyvisites:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:matthieu_aubry:phpmyvisites:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:matthieu_aubry:phpmyvisites:1.2_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:matthieu_aubry:phpmyvisites:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:matthieu_aubry:phpmyvisites:2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:matthieu_aubry:phpmyvisites:0.1_beta</vuln:product>
      <vuln:product>cpe:/a:matthieu_aubry:phpmyvisites:1.0</vuln:product>
      <vuln:product>cpe:/a:matthieu_aubry:phpmyvisites:1.1</vuln:product>
      <vuln:product>cpe:/a:matthieu_aubry:phpmyvisites:1.2</vuln:product>
      <vuln:product>cpe:/a:matthieu_aubry:phpmyvisites:1.2.1</vuln:product>
      <vuln:product>cpe:/a:matthieu_aubry:phpmyvisites:1.2.2</vuln:product>
      <vuln:product>cpe:/a:matthieu_aubry:phpmyvisites:1.2_beta</vuln:product>
      <vuln:product>cpe:/a:matthieu_aubry:phpmyvisites:1.3</vuln:product>
      <vuln:product>cpe:/a:matthieu_aubry:phpmyvisites:2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0893</vuln:cve-id>
    <vuln:published-datetime>2007-02-12T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:06.200-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://marc.info/?l=full-disclosure&amp;m=117121596803908&amp;w=2" xml:lang="en">20070211 Multiple vulnerabilities in phpMyVisites</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459792/100/0/threaded" xml:lang="en">20070211 Multiple vulnerabilities in phpMyVisites</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22516" xml:lang="en">22516</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32433" xml:lang="en">phpmyvisites-pmvckview-file-include(32433)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in phpMyVisites before 2.2 allows remote attackers to include arbitrary files via leading ".." sequences on the pmv_ck_view COOKIE parameter, which bypasses the protection scheme.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0894">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.3.15"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.13"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4.14"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4_beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4_beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4_beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4_beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4_beta5"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.4_beta6"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5_alpha1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5_alpha2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5_beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5_beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5_beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5_beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5_rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5_rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.5_rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.5_r14348"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.8.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.9.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.9.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.1.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.2.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.2.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.2.2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.2.3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.2.4</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.2.5</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.2.6</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.4</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.5</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.6</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.7</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.8</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.9</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.10</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.11</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.12</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.13</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.14</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.3.15</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.4</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.5</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.6</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.7</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.8</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.9</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.10</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.11</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.12</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.13</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4.14</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4_beta1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4_beta2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4_beta3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4_beta4</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4_beta5</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.4_beta6</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5.2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5.3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5.4</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5.5</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5.6</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5.7</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5_alpha1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5_alpha2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5_beta1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5_beta2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5_beta3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5_beta4</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5_rc2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5_rc3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.5_rc4</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.3</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.4</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.5</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.5_r14348</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.6.6</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.7.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.7.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.8.0</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.8.1</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.8.2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.9.0:rc2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.9.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0894</vuln:cve-id>
    <vuln:published-datetime>2007-02-12T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:06.623-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugzilla.wikimedia.org/show_bug.cgi?id=8819" xml:lang="en">http://bugzilla.wikimedia.org/show_bug.cgi?id=8819</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://svn.wikimedia.org/viewvc/mediawiki?view=rev&amp;revision=19681" xml:lang="en">http://svn.wikimedia.org/viewvc/mediawiki?view=rev&amp;revision=19681</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459793/100/0/threaded" xml:lang="en">20070211 MediaWiki Full Path Disclosure Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://zone14.free.fr/advisories/7/" xml:lang="en">http://zone14.free.fr/advisories/7/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32440" xml:lang="en">mediawiki-multiple-scripts-path-disclosure(32440)</vuln:reference>
    </vuln:references>
    <vuln:summary>MediaWiki before 1.9.2 allows remote attackers to obtain sensitive information via a direct request to (1) Simple.deps.php, (2) MonoBook.deps.php, (3) MySkin.deps.php, or (4) Chick.deps.php in wiki/skins, which shows the installation path in the resulting error message.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0895">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:9.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:10.0::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:9.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:10.0::sparc</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0895</vuln:cve-id>
    <vuln:published-datetime>2007-02-12T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:37.090-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8272" name="oval:org.mitre.oval:def:8272"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102782-1" xml:lang="en">102782</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2007-102.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2007-102.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0543" xml:lang="en">ADV-2007-0543</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32399" xml:lang="en">solaris-rm-dos(32399)</vuln:reference>
    </vuln:references>
    <vuln:summary>Race condition in recursive directory deletion with the (1) -r or (2) -R option in rm in Solaris 8 through 10 before 20070208 allows local users to delete files and directories as the user running rm by moving a low-level directory to a higher level as it is being deleted, which causes rm to chdir to a ".." directory that is higher than expected, possibly up to the root file system, a related issue to CVE-2002-0435.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0896">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox"/>
        <cpe-lang:fact-ref name="cpe:/a:sage:sage"/>
        <cpe-lang:fact-ref name="cpe:/a:sage:sage:1.0_beta_3"/>
        <cpe-lang:fact-ref name="cpe:/a:sage:sage:1.3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:sage:sage:1.3.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:firefox</vuln:product>
      <vuln:product>cpe:/a:sage:sage</vuln:product>
      <vuln:product>cpe:/a:sage:sage:1.0_beta_3</vuln:product>
      <vuln:product>cpe:/a:sage:sage:1.3.6</vuln:product>
      <vuln:product>cpe:/a:sage:sage:1.3.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0896</vuln:cve-id>
    <vuln:published-datetime>2007-02-13T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:29.487-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>JVN</vuln:source>
      <vuln:reference href="http://jvn.jp/jp/JVN%2384430861/index.html" xml:lang="en">JVN#84430861</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://mozdev.org/bugs/show_bug.cgi?id=16320" xml:lang="en">http://mozdev.org/bugs/show_bug.cgi?id=16320</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sage.mozdev.org/blog/archives/2007/1/sage_1_3_10_released.html" xml:lang="en">http://sage.mozdev.org/blog/archives/2007/1/sage_1_3_10_released.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22493" xml:lang="en">22493</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017624" xml:lang="en">1017624</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32395" xml:lang="en">sage-rssfeed-xss(32395)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the (1) Sage before 1.3.10, and (2) Sage++ extensions for Firefox, allows remote attackers to inject arbitrary web script or HTML via a "&lt;SCRIPT/=''SRC='" sequence in an RSS feed, a different vulnerability than CVE-2006-4712.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0897">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.20"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.21"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.22"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.23"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.24"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.51"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.52"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.53"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.54"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.60"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.60p"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.65"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.67"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.68"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.68.1"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.70"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.71"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.72"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.73"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.74"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.75"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.75.1"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.80"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.80_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.80_rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.80_rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.80_rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.81"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.81_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.82"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.83"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.84"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.84_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.84_rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.85"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.85.1"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.86"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.86.1"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.86.2"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.86_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.87"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.87.1"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.88"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.88.1"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.88.3"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.88.4"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.88.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.15</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.20</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.21</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.22</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.23</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.24</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.51</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.52</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.53</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.54</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.60</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.60p</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.65</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.67</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.68</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.68.1</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.70</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.71</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.72</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.73</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.74</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.75</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.75.1</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.80</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.80_rc1</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.80_rc2</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.80_rc3</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.80_rc4</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.81</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.81_rc1</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.82</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.83</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.84</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.84_rc1</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.84_rc2</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.85</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.85.1</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.86</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.86.1</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.86.2</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.86_rc1</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.87</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.87.1</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.88</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.88.1</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.88.3</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.88.4</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.88.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0897</vuln:cve-id>
    <vuln:published-datetime>2007-02-16T14:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:29.563-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307562" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307562</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=475" xml:lang="en">20070215 Multiple Vendor ClamAV CAB File Denial of Service Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" xml:lang="en">APPLE-SA-2008-03-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Feb/0004.html" xml:lang="en">SUSE-SA:2007:017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200703-03.xml" xml:lang="en">GLSA-200703-03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1263" xml:lang="en">DSA-1263</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:043" xml:lang="en">MDKSA-2007:043</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22580" xml:lang="en">22580</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017659" xml:lang="en">1017659</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0623" xml:lang="en">ADV-2007-0623</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0924/references" xml:lang="en">ADV-2008-0924</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32531" xml:lang="en">clamav-cabfile-dos(32531)</vuln:reference>
    </vuln:references>
    <vuln:summary>Clam AntiVirus ClamAV before 0.90 does not close open file descriptors under certain conditions, which allows remote attackers to cause a denial of service (file descriptor consumption and failed scans) via CAB archives with a cabinet header record length of zero, which causes a function to return without closing a file descriptor.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0898">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.20"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.21"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.22"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.23"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.24"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.51"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.52"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.53"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.54"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.60"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.60p"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.65"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.67"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.68"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.68.1"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.70"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.71"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.72"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.73"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.74"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.75"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.75.1"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.80"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.80_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.80_rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.80_rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.80_rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.81"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.81_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.82"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.83"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.84"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.84_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.84_rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.85"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.85.1"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.86"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.86.1"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.86.2"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.86_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.87"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.87.1"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.88"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.88.1"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.88.3"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.88.4"/>
        <cpe-lang:fact-ref name="cpe:/a:clam_anti-virus:clamav:0.88.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.15</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.20</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.21</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.22</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.23</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.24</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.51</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.52</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.53</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.54</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.60</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.60p</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.65</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.67</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.68</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.68.1</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.70</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.71</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.72</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.73</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.74</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.75</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.75.1</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.80</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.80_rc1</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.80_rc2</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.80_rc3</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.80_rc4</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.81</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.81_rc1</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.82</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.83</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.84</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.84_rc1</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.84_rc2</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.85</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.85.1</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.86</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.86.1</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.86.2</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.86_rc1</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.87</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.87.1</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.88</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.88.1</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.88.3</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.88.4</vuln:product>
      <vuln:product>cpe:/a:clam_anti-virus:clamav:0.88.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0898</vuln:cve-id>
    <vuln:published-datetime>2007-02-16T14:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:29.627-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307562" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307562</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=476" xml:lang="en">20070215 Multiple Vendor ClamAV MIME Parsing Directory Traversal Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" xml:lang="en">APPLE-SA-2008-03-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Feb/0004.html" xml:lang="en">SUSE-SA:2007:017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200703-03.xml" xml:lang="en">GLSA-200703-03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1263" xml:lang="en">DSA-1263</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:043" xml:lang="en">MDKSA-2007:043</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22581" xml:lang="en">22581</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017660" xml:lang="en">1017660</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0623" xml:lang="en">ADV-2007-0623</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0924/references" xml:lang="en">ADV-2008-0924</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32535" xml:lang="en">clamav-mimeheader-directory-traversal(32535)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in clamd in Clam AntiVirus ClamAV before 0.90 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the id MIME header parameter in a multi-part message.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0900">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:tagit:tagboard:2.1.b_build_2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:tagit:tagboard:2.1.b_build_2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0900</vuln:cve-id>
    <vuln:published-datetime>2007-02-13T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:29.687-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://advisories.echo.or.id/adv/adv65-K-159-2007.txt" xml:lang="en">http://advisories.echo.or.id/adv/adv65-K-159-2007.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22518" xml:lang="en">22518</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0557" xml:lang="en">ADV-2007-0557</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32436" xml:lang="en">tagit-multiplescripts-file-include(32436)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple PHP remote file inclusion vulnerabilities in TagIt! Tagboard 2.1.B Build 2 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) configpath parameter to (a) tagviewer.php, (b) tag_process.php, and (c) CONFIG/errmsg.inc.php; and (d) addTagmin.php, (e) ban_watch.php, (f) delTagmin.php, (g) delTag.php, (h) editTagmin.php, (i) editTag.php, (j) manageTagmins.php, and (k) verify.php in tagmin/; the (2) adminpath parameter to (l) tagviewer.php, (m) tag_process.php, and (n) tagmin/index.php; and the (3) admin parameter to (o) readconf.php, (p) updateconf.php, (q) updatefilter.php, and (r) wordfilter.php in tagmin/; different vectors than CVE-2006-5249.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0901">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:moinmoin:moinmoin:1.5.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:moinmoin:moinmoin:1.5.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0901</vuln:cve-id>
    <vuln:published-datetime>2007-02-13T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:42:23.860-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22515" xml:lang="en">22515</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-423-1" xml:lang="en">USN-423-1</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Info pages in MoinMoin 1.5.7 allow remote attackers to inject arbitrary web script or HTML via the (1) hitcounts and (2) general parameters, different vectors than CVE-2007-0857.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0902">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:moinmoin:moinmoin:1.5.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:moinmoin:moinmoin:1.5.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0902</vuln:cve-id>
    <vuln:published-datetime>2007-02-13T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:42:24.250-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22515" xml:lang="en">22515</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-423-1" xml:lang="en">USN-423-1</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the "Show debugging information" feature in MoinMoin 1.5.7 allows remote attackers to obtain sensitive information.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0903">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:process-one:ejabberd:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:process-one:ejabberd:0.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:process-one:ejabberd:0.9.8"/>
        <cpe-lang:fact-ref name="cpe:/a:process-one:ejabberd:1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:process-one:ejabberd:1.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:process-one:ejabberd:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:process-one:ejabberd:1.1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:process-one:ejabberd:0.9</vuln:product>
      <vuln:product>cpe:/a:process-one:ejabberd:0.9.1</vuln:product>
      <vuln:product>cpe:/a:process-one:ejabberd:0.9.8</vuln:product>
      <vuln:product>cpe:/a:process-one:ejabberd:1.0.0</vuln:product>
      <vuln:product>cpe:/a:process-one:ejabberd:1.1.0</vuln:product>
      <vuln:product>cpe:/a:process-one:ejabberd:1.1.1</vuln:product>
      <vuln:product>cpe:/a:process-one:ejabberd:1.1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0903</vuln:cve-id>
    <vuln:published-datetime>2007-02-13T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:29.750-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.process-one.net/en/ejabberd/release_notes/release_note_ejabberd_113/" xml:lang="en">http://www.process-one.net/en/ejabberd/release_notes/release_note_ejabberd_113/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22525" xml:lang="en">22525</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0570" xml:lang="en">ADV-2007-0570</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32437" xml:lang="en">ejabberd-modrosterodbc-unspecified(32437)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the mod_roster_odbc module in ejabberd before 1.1.3 has unknown impact and attack vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0904">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:lightro:lightro_cms:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:lightro:lightro_cms:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0904</vuln:cve-id>
    <vuln:published-datetime>2007-02-13T15:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:06.270-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0540" xml:lang="en">ADV-2007-0540</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32347" xml:lang="en">lightro-index-sql-injection(32347)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3286" xml:lang="en">3286</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in projects.php in LightRO CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter to index.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0905">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.1:patch1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.1:patch2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.3:patch1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2::dev"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:trustix:secure_linux:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:trustix:secure_linux:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:php:3.0</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.1</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.2</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.3</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.4</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.5</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.6</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.7</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.8</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.9</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.10</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.11</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.12</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.13</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.14</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.15</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.16</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.17</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.18</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.1:patch1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.1:patch2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.3:patch1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.5</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.6</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2::dev</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.5</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.6</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.7</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.8</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.9</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.10</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.11</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.4</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.4</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.5</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.0</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.4</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.5</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.6</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.0</vuln:product>
      <vuln:product>cpe:/o:trustix:secure_linux:2.2</vuln:product>
      <vuln:product>cpe:/o:trustix:secure_linux:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0905</vuln:cve-id>
    <vuln:published-datetime>2007-02-13T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:35.747-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OPENPKG</vuln:source>
      <vuln:reference href="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.010.html" xml:lang="en">OpenPKG-SA-2007.010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.php.net/ChangeLog-5.php#5.2.1" xml:lang="en">http://www.php.net/ChangeLog-5.php#5.2.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.php.net/releases/5_2_1.php" xml:lang="en">http://www.php.net/releases/5_2_1.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22496" xml:lang="en">22496</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2007/0009/" xml:lang="en">2007-0009</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0546" xml:lang="en">ADV-2007-0546</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP before 5.2.1 allows attackers to bypass safe_mode and open_basedir restrictions via unspecified vectors in the session extension.  NOTE: it is possible that this issue is a duplicate of CVE-2006-6383.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0906">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.1:patch1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.1:patch2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.3:patch1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2::dev"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:trustix:secure_linux:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:trustix:secure_linux:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:php:3.0</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.1</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.2</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.3</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.4</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.5</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.6</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.7</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.8</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.9</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.10</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.11</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.12</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.13</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.14</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.15</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.16</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.17</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.18</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.1:patch1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.1:patch2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.3:patch1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.5</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.6</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2::dev</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.5</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.6</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.7</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.8</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.9</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.10</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.11</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.4</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.4</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.5</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.0</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.4</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.5</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.6</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.0</vuln:product>
      <vuln:product>cpe:/o:trustix:secure_linux:2.2</vuln:product>
      <vuln:product>cpe:/o:trustix:secure_linux:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0906</vuln:cve-id>
    <vuln:published-datetime>2007-02-13T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:35.747-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8992" name="oval:org.mitre.oval:def:8992"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc" xml:lang="en">20070201-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2007-07/msg00006.html" xml:lang="en">SUSE-SA:2007:044</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0003.html" xml:lang="en">SUSE-SA:2007:020</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2007-0089.html" xml:lang="en">RHSA-2007:0089</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200703-21.xml" xml:lang="en">GLSA-200703-21</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2007-101.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2007-101.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2007-136.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2007-136.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:048" xml:lang="en">MDKSA-2007:048</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OPENPKG</vuln:source>
      <vuln:reference href="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.010.html" xml:lang="en">OpenPKG-SA-2007.010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.php.net/ChangeLog-5.php#5.2.1" xml:lang="en">http://www.php.net/ChangeLog-5.php#5.2.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.php.net/releases/5_2_1.php" xml:lang="en">http://www.php.net/releases/5_2_1.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0076.html" xml:lang="en">RHSA-2007:0076</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0081.html" xml:lang="en">RHSA-2007:0081</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0082.html" xml:lang="en">RHSA-2007:0082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0088.html" xml:lang="en">RHSA-2007:0088</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461462/100/0/threaded" xml:lang="en">20070227 rPSA-2007-0043-1 php php-mysql php-pgsql</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/466166/100/0/threaded" xml:lang="en">20070418 rPSA-2007-0073-1 php php-mysql php-pgsql</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22496" xml:lang="en">22496</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017671" xml:lang="en">1017671</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2007/0009/" xml:lang="en">2007-0009</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-424-1" xml:lang="en">USN-424-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-424-2" xml:lang="en">USN-424-2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.us.debian.org/security/2007/dsa-1264" xml:lang="en">DSA-1264</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0546" xml:lang="en">ADV-2007-0546</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1088" xml:lang="en">https://issues.rpath.com/browse/RPL-1088</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1268" xml:lang="en">https://issues.rpath.com/browse/RPL-1268</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in PHP before 5.2.1 allow attackers to cause a denial of service and possibly execute arbitrary code via unspecified vectors in the (1) session, (2) zip, (3) imap, and (4) sqlite extensions; (5) stream filters; and the (6) str_replace, (7) mail, (8) ibase_delete_user, (9) ibase_add_user, and (10) ibase_modify_user functions.  NOTE: vector 6 might actually be an integer overflow (CVE-2007-1885).  NOTE: as of 20070411, vector (3) might involve the imap_mail_compose function (CVE-2007-1825).</vuln:summary>
  </entry>
  <entry id="CVE-2007-0907">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.1:patch1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.1:patch2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.3:patch1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2::dev"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:trustix:secure_linux:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:trustix:secure_linux:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:php:3.0</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.1</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.2</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.3</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.4</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.5</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.6</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.7</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.8</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.9</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.10</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.11</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.12</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.13</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.14</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.15</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.16</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.17</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.18</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.1:patch1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.1:patch2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.3:patch1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.5</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.6</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2::dev</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.5</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.6</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.7</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.8</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.9</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.10</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.11</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.4</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.4</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.5</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.0</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.4</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.5</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.6</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.0</vuln:product>
      <vuln:product>cpe:/o:trustix:secure_linux:2.2</vuln:product>
      <vuln:product>cpe:/o:trustix:secure_linux:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0907</vuln:cve-id>
    <vuln:published-datetime>2007-02-13T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:35.747-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11321" name="oval:org.mitre.oval:def:11321"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc" xml:lang="en">20070201-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0003.html" xml:lang="en">SUSE-SA:2007:020</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2007-0089.html" xml:lang="en">RHSA-2007:0089</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200703-21.xml" xml:lang="en">GLSA-200703-21</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2007-101.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2007-101.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2007-136.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2007-136.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:048" xml:lang="en">MDKSA-2007:048</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OPENPKG</vuln:source>
      <vuln:reference href="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.010.html" xml:lang="en">OpenPKG-SA-2007.010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.php.net/ChangeLog-5.php#5.2.1" xml:lang="en">http://www.php.net/ChangeLog-5.php#5.2.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.php.net/releases/5_2_1.php" xml:lang="en">http://www.php.net/releases/5_2_1.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0076.html" xml:lang="en">RHSA-2007:0076</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0081.html" xml:lang="en">RHSA-2007:0081</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0082.html" xml:lang="en">RHSA-2007:0082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0088.html" xml:lang="en">RHSA-2007:0088</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461462/100/0/threaded" xml:lang="en">20070227 rPSA-2007-0043-1 php php-mysql php-pgsql</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22496" xml:lang="en">22496</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017671" xml:lang="en">1017671</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2007/0009/" xml:lang="en">2007-0009</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-424-1" xml:lang="en">USN-424-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-424-2" xml:lang="en">USN-424-2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.us.debian.org/security/2007/dsa-1264" xml:lang="en">DSA-1264</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0546" xml:lang="en">ADV-2007-0546</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1088" xml:lang="en">https://issues.rpath.com/browse/RPL-1088</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer underflow in PHP before 5.2.1 allows attackers to cause a denial of service via unspecified vectors involving the sapi_header_op function.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0908">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0:beta_4_patch1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.1:rc"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.1:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.2:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.3:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.3:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.4:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.4:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.4:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.4:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.4:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.4:rc6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.5:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.5:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.5:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.5:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.5:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.5:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.5:rc6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.5:rc7"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.5:rc8"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.6:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.6:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.6:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.6:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.6:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.0:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.0:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.0:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.0:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.0:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.1:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.1:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.3:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.3:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.0:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.0:alpha1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.0:alpha2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.0:alpha3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.0:dev"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.0:pre1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.0:pre2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.0:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.2:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.2:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.2:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.2:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.3:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.3:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.3:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.3:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.4:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.4:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.4:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.5:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.5:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.5:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.5:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.5:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.6:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.6:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.6:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.6:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.7:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.7:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.9:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.9:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.9:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.10:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.10:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.10:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.11:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.11:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.11:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.0:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.1:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.2:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.2:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.3:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.3:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.4:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.1:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.1:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.1:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.2:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.3:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.3:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.4:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.4:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.5:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.5:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.5:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.0:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.0:rc2-pre"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.0:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.0:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.0:rc6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.2:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.2:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.3:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.3:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.3:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.5:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.5:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.0:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.0:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.0:rc6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:5.10"/>
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:6.06::~~lts~~~"/>
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:6.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:php:4.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0:beta1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0:beta2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0:beta3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0:beta4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0:beta_4_patch1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.1:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.1:rc</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.1:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.2:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.3:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.3:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.4:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.4:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.4:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.4:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.4:rc4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.4:rc5</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.4:rc6</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.5</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.5:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.5:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.5:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.5:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.5:rc4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.5:rc5</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.5:rc6</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.5:rc7</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.5:rc8</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.6</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.6:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.6:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.6:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.6:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.6:rc4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.0:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.0:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.0:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.0:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.0:rc4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.0:rc5</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.0:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.0:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.0:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.0:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.0:rc4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.1:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.1:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.1:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.3:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.3:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.3:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.0:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.0:alpha1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.0:alpha2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.0:alpha3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.0:dev</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.0:pre1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.0:pre2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.0:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.0:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.0:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.0:rc4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.2:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.2:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.2:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.2:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.2:rc4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.3:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.3:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.3:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.3:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.3:rc4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.4:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.4:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.4:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.4:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.5</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.5:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.5:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.5:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.5:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.5:rc4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.6</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.6:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.6:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.6:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.6:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.7</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.7:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.7:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.8</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.9</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.9:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.9:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.9:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.10</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.10:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.10:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.10:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.11</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.11:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.11:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.11:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.0:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.0:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.0:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.1:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.1:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.2:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.2:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.2:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.3:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.3:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.3:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.4:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.4:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:-</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:beta1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:beta2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:beta3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:beta4</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.1:-</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.1:beta1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.1:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.1:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.2:-</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.2:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.3:-</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.3:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.3:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.4</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.4:-</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.4:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.4:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.5</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.5:-</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.5:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.5:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.0</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.0:-</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.0:beta1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.0:beta2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.0:beta3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.0:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.0:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.0:rc2-pre</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.0:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.0:rc4</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.0:rc5</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.0:rc6</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.2:-</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.2:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.2:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.3:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.3:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.3:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.4</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.5</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.5:-</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.5:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.6</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.0</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.0:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.0:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.0:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.0:rc4</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.0:rc5</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.0:rc6</vuln:product>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:5.10</vuln:product>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:6.06::~~lts~~~</vuln:product>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:6.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0908</vuln:cve-id>
    <vuln:published-datetime>2007-02-13T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:21.043-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2018-10-18T09:12:29.887-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11185" name="oval:org.mitre.oval:def:11185"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc" xml:lang="en">20070201-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0003.html" xml:lang="en">SUSE-SA:2007:020</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2007-0089.html" xml:lang="en">RHSA-2007:0089</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200703-21.xml" xml:lang="en">GLSA-200703-21</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2321" xml:lang="en">2321</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2007-101.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2007-101.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2007-136.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2007-136.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:048" xml:lang="en">MDKSA-2007:048</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>OPENPKG</vuln:source>
      <vuln:reference href="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.010.html" xml:lang="en">OpenPKG-SA-2007.010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.php.net/ChangeLog-5.php#5.2.1" xml:lang="en">http://www.php.net/ChangeLog-5.php#5.2.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.php.net/releases/5_2_1.php" xml:lang="en">http://www.php.net/releases/5_2_1.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.php-security.org/MOPB/MOPB-11-2007.html" xml:lang="en">http://www.php-security.org/MOPB/MOPB-11-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0076.html" xml:lang="en">RHSA-2007:0076</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0081.html" xml:lang="en">RHSA-2007:0081</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0082.html" xml:lang="en">RHSA-2007:0082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0088.html" xml:lang="en">RHSA-2007:0088</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461462/100/0/threaded" xml:lang="en">20070227 rPSA-2007-0043-1 php php-mysql php-pgsql</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22496" xml:lang="en">22496</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22806" xml:lang="en">22806</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017671" xml:lang="en">1017671</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2007/0009/" xml:lang="en">2007-0009</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-424-1" xml:lang="en">USN-424-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-424-2" xml:lang="en">USN-424-2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.us.debian.org/security/2007/dsa-1264" xml:lang="en">DSA-1264</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0546" xml:lang="en">ADV-2007-0546</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32493" xml:lang="en">php-wddx-information-disclosure(32493)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1088" xml:lang="en">https://issues.rpath.com/browse/RPL-1088</vuln:reference>
    </vuln:references>
    <vuln:summary>The WDDX deserializer in the wddx extension in PHP 5 before 5.2.1 and PHP 4 before 4.4.5 does not properly initialize the key_length variable for a numerical key, which allows context-dependent attackers to read stack memory via a wddxPacket element that contains a variable with a string name before a numerical variable.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0909">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.1:patch1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.1:patch2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.3:patch1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2::dev"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:trustix:secure_linux:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:trustix:secure_linux:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:php:3.0</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.1</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.2</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.3</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.4</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.5</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.6</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.7</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.8</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.9</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.10</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.11</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.12</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.13</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.14</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.15</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.16</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.17</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.18</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.1:patch1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.1:patch2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.3:patch1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.5</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.6</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2::dev</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.5</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.6</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.7</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.8</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.9</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.10</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.11</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.4</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.4</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.5</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.0</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.4</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.5</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.6</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.0</vuln:product>
      <vuln:product>cpe:/o:trustix:secure_linux:2.2</vuln:product>
      <vuln:product>cpe:/o:trustix:secure_linux:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0909</vuln:cve-id>
    <vuln:published-datetime>2007-02-13T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:35.747-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9722" name="oval:org.mitre.oval:def:9722"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc" xml:lang="en">20070201-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0003.html" xml:lang="en">SUSE-SA:2007:020</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2007-0089.html" xml:lang="en">RHSA-2007:0089</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200703-21.xml" xml:lang="en">GLSA-200703-21</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2007-101.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2007-101.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2007-136.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2007-136.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:048" xml:lang="en">MDKSA-2007:048</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OPENPKG</vuln:source>
      <vuln:reference href="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.010.html" xml:lang="en">OpenPKG-SA-2007.010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.php.net/ChangeLog-5.php#5.2.1" xml:lang="en">http://www.php.net/ChangeLog-5.php#5.2.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.php.net/releases/5_2_1.php" xml:lang="en">http://www.php.net/releases/5_2_1.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0076.html" xml:lang="en">RHSA-2007:0076</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0081.html" xml:lang="en">RHSA-2007:0081</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0082.html" xml:lang="en">RHSA-2007:0082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0088.html" xml:lang="en">RHSA-2007:0088</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461462/100/0/threaded" xml:lang="en">20070227 rPSA-2007-0043-1 php php-mysql php-pgsql</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22496" xml:lang="en">22496</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017671" xml:lang="en">1017671</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2007/0009/" xml:lang="en">2007-0009</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-424-1" xml:lang="en">USN-424-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-424-2" xml:lang="en">USN-424-2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.us.debian.org/security/2007/dsa-1264" xml:lang="en">DSA-1264</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0546" xml:lang="en">ADV-2007-0546</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1088" xml:lang="en">https://issues.rpath.com/browse/RPL-1088</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple format string vulnerabilities in PHP before 5.2.1 might allow attackers to execute arbitrary code via format string specifiers to (1) all of the *print functions on 64-bit systems, and (2) the odbc_result_all function.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0910">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:3.0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.1:patch1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.1:patch2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.3:patch1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2::dev"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:trustix:secure_linux:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:trustix:secure_linux:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:php:3.0</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.1</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.2</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.3</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.4</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.5</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.6</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.7</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.8</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.9</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.10</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.11</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.12</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.13</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.14</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.15</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.16</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.17</vuln:product>
      <vuln:product>cpe:/a:php:php:3.0.18</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.1:patch1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.1:patch2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.3:patch1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.5</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.6</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2::dev</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.5</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.6</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.7</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.8</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.9</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.10</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.11</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.4</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.4</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.5</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.0</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.4</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.5</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.6</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.0</vuln:product>
      <vuln:product>cpe:/o:trustix:secure_linux:2.2</vuln:product>
      <vuln:product>cpe:/o:trustix:secure_linux:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0910</vuln:cve-id>
    <vuln:published-datetime>2007-02-13T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:35.747-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9514" name="oval:org.mitre.oval:def:9514"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc" xml:lang="en">20070201-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0003.html" xml:lang="en">SUSE-SA:2007:020</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2007-0089.html" xml:lang="en">RHSA-2007:0089</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200703-21.xml" xml:lang="en">GLSA-200703-21</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2007-101.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2007-101.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2007-136.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2007-136.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:048" xml:lang="en">MDKSA-2007:048</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OPENPKG</vuln:source>
      <vuln:reference href="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.010.html" xml:lang="en">OpenPKG-SA-2007.010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.php.net/ChangeLog-5.php#5.2.1" xml:lang="en">http://www.php.net/ChangeLog-5.php#5.2.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.php.net/releases/5_2_1.php" xml:lang="en">http://www.php.net/releases/5_2_1.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0076.html" xml:lang="en">RHSA-2007:0076</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0081.html" xml:lang="en">RHSA-2007:0081</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0082.html" xml:lang="en">RHSA-2007:0082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0088.html" xml:lang="en">RHSA-2007:0088</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461462/100/0/threaded" xml:lang="en">20070227 rPSA-2007-0043-1 php php-mysql php-pgsql</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/466166/100/0/threaded" xml:lang="en">20070418 rPSA-2007-0073-1 php php-mysql php-pgsql</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22496" xml:lang="en">22496</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017671" xml:lang="en">1017671</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2007/0009/" xml:lang="en">2007-0009</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-424-1" xml:lang="en">USN-424-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-424-2" xml:lang="en">USN-424-2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.us.debian.org/security/2007/dsa-1264" xml:lang="en">DSA-1264</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0546" xml:lang="en">ADV-2007-0546</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1088" xml:lang="en">https://issues.rpath.com/browse/RPL-1088</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1268" xml:lang="en">https://issues.rpath.com/browse/RPL-1268</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in PHP before 5.2.1 allows attackers to "clobber" certain super-global variables via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0911">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:php:5.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0911</vuln:cve-id>
    <vuln:published-datetime>2007-02-13T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:29.280-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://cvs.php.net/viewvc.cgi/php-src/ext/standard/string.c?r1=1.445.2.14.2.36&amp;r2=1.445.2.14.2.37" xml:lang="en">http://cvs.php.net/viewvc.cgi/php-src/ext/standard/string.c?r1=1.445.2.14.2.36&amp;r2=1.445.2.14.2.37</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0003.html" xml:lang="en">SUSE-SA:2007:020</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://marc.info/?l=php-dev&amp;m=117104930526516&amp;w=2" xml:lang="en">[php-dev] 20070209 PHP 5.2.1 crashing Apache/IIS...</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://marc.info/?l=php-dev&amp;m=117106751715609&amp;w=2" xml:lang="en">[php-dev] 20070210 Re: PHP 5.2.1 crashing Apache/IIS...</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200703-21.xml" xml:lang="en">GLSA-200703-21</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459856/100/0/threaded" xml:lang="en">20070209 PHP 5.2.1 crash bug</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22505" xml:lang="en">22505</vuln:reference>
    </vuln:references>
    <vuln:summary>Off-by-one error in the str_ireplace function in PHP 5.2.1 might allow context-dependent attackers to cause a denial of service (crash).</vuln:summary>
  </entry>
  <entry id="CVE-2007-0912">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:jportal:jportal_web_server:2.3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:jportal:jportal_web_server:2.3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0912</vuln:cve-id>
    <vuln:published-datetime>2007-02-13T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:29.717-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2239" xml:lang="en">2239</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459827/100/0/threaded" xml:lang="en">20070211 Jportal 2.3.1 CSRF vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32458" xml:lang="en">jportal-admin-csrf(32458)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-Site Request Forgery (CSRF) vulnerability in admin/admin.adm.php in Jportal 2.3.1, and possibly earlier, allows remote attackers to perform privileged actions as administrators by tricking the admin into accessing a URL with modified arguments to admin/admin.adm.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0913">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:powerpoint"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:powerpoint</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0913</vuln:cve-id>
    <vuln:published-datetime>2007-02-13T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:42:28.610-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2007-021312-5133-99&amp;tabid=2" xml:lang="en">http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2007-021312-5133-99&amp;tabid=2</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Microsoft Powerpoint allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as exploited by Trojan.PPDropper.G.  NOTE: as of 20070213, it is not clear whether this is the same issue as CVE-2006-5296, CVE-2006-4694, CVE-2006-3876, CVE-2006-3877, or older issues.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0914">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:10.0::sparc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:10.0::sparc</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0914</vuln:cve-id>
    <vuln:published-datetime>2007-02-13T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:40.707-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2120" name="oval:org.mitre.oval:def:2120"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102796-1" xml:lang="en">102796</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22550" xml:lang="en">22550</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017649" xml:lang="en">1017649</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0588" xml:lang="en">ADV-2007-0588</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32484" xml:lang="en">solaris-tcp-race-condition-dos(32484)</vuln:reference>
    </vuln:references>
    <vuln:summary>Race condition in the TCP subsystem for Solaris 10 allows remote attackers to cause a denial of service (system panic) via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0915">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux:11.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0915</vuln:cve-id>
    <vuln:published-datetime>2007-02-13T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:30.093-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=474" xml:lang="en">20070213 Hewlett-Packard HP-UX SLSd Arbitrary File Creation Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22551" xml:lang="en">22551</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017630" xml:lang="en">1017630</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0590" xml:lang="en">ADV-2007-0590</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00862809" xml:lang="en">HPSBUX02191</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32471" xml:lang="en">hpux-slsd-privilege-escalation(32471)</vuln:reference>
    </vuln:references>
    <vuln:summary>Distributed SLS daemon (SLSd) on HP-UX B.11.11 allows remote attackers to overwrite arbitrary files and gain privileges via a crafted RPC request.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0916">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.11"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.23"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux:11.11</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.23</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0916</vuln:cve-id>
    <vuln:published-datetime>2007-02-13T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:40.767-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5239" name="oval:org.mitre.oval:def:5239"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22546" xml:lang="en">22546</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017629" xml:lang="en">1017629</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0596" xml:lang="en">ADV-2007-0596</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00863839" xml:lang="en">HPSBUX02192</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32468" xml:lang="en">hpux-arpa-dos(32468)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport functionality in HP-UX B.11.11 and B.11.23 allows local users to cause an unspecified denial of service via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0917">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3t"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xq"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xr"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xs"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xw"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xx"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3xy"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3ya"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3yd"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3yg"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3yh"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3yi"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3yj"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3yk"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3ym"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3yq"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3ys"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3yt"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3yx"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3yz"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4mr"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4t"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4xa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.4xb"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:cisco:ios:12.3t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xq</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xr</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xs</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xw</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xx</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3xy</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3ya</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3yd</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3yg</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3yh</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3yi</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3yj</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3yk</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3ym</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3yq</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3ys</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3yt</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3yx</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3yz</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4mr</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4xa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.4xb</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0917</vuln:cve-id>
    <vuln:published-datetime>2007-02-13T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:40.830-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5858" name="oval:org.mitre.oval:def:5858"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e0a5b.shtml" xml:lang="en">20070213 Multiple IOS IPS Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.cisco.com/en/US/products/products_security_response09186a00807e0a5e.html" xml:lang="en">http://www.cisco.com/en/US/products/products_security_response09186a00807e0a5e.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22549" xml:lang="en">22549</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017631" xml:lang="en">1017631</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0597" xml:lang="en">ADV-2007-0597</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32473" xml:lang="en">cisco-ios-ips-security-bypass(32473)</vuln:reference>
    </vuln:references>
    <vuln:summary>The Intrusion Prevention System (IPS) feature for Cisco IOS 12.4XE to 12.3T allows remote attackers to bypass IPS signatures that use regular expressions via fragmented packets.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0918">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios:12.3xq"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios:12.3xr"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios:12.3xs"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios:12.3xw"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios:12.3xx"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios:12.3xy"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios:12.3ya"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios:12.3yd"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios:12.3yg"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios:12.3yh"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios:12.3yj"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios:12.3yk"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios:12.3ym"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios:12.3yq"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios:12.3ys"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios:12.3yt"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios:12.3yx"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios:12.3yz"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios:12.4"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios:12.4mr"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios:12.4t"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios:12.4xa"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:ios:12.4xb"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3t"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.3yi"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:cisco:ios:12.3xq</vuln:product>
      <vuln:product>cpe:/h:cisco:ios:12.3xr</vuln:product>
      <vuln:product>cpe:/h:cisco:ios:12.3xs</vuln:product>
      <vuln:product>cpe:/h:cisco:ios:12.3xw</vuln:product>
      <vuln:product>cpe:/h:cisco:ios:12.3xx</vuln:product>
      <vuln:product>cpe:/h:cisco:ios:12.3xy</vuln:product>
      <vuln:product>cpe:/h:cisco:ios:12.3ya</vuln:product>
      <vuln:product>cpe:/h:cisco:ios:12.3yd</vuln:product>
      <vuln:product>cpe:/h:cisco:ios:12.3yg</vuln:product>
      <vuln:product>cpe:/h:cisco:ios:12.3yh</vuln:product>
      <vuln:product>cpe:/h:cisco:ios:12.3yj</vuln:product>
      <vuln:product>cpe:/h:cisco:ios:12.3yk</vuln:product>
      <vuln:product>cpe:/h:cisco:ios:12.3ym</vuln:product>
      <vuln:product>cpe:/h:cisco:ios:12.3yq</vuln:product>
      <vuln:product>cpe:/h:cisco:ios:12.3ys</vuln:product>
      <vuln:product>cpe:/h:cisco:ios:12.3yt</vuln:product>
      <vuln:product>cpe:/h:cisco:ios:12.3yx</vuln:product>
      <vuln:product>cpe:/h:cisco:ios:12.3yz</vuln:product>
      <vuln:product>cpe:/h:cisco:ios:12.4</vuln:product>
      <vuln:product>cpe:/h:cisco:ios:12.4mr</vuln:product>
      <vuln:product>cpe:/h:cisco:ios:12.4t</vuln:product>
      <vuln:product>cpe:/h:cisco:ios:12.4xa</vuln:product>
      <vuln:product>cpe:/h:cisco:ios:12.4xb</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.3yi</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0918</vuln:cve-id>
    <vuln:published-datetime>2007-02-13T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:57.183-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5832" name="oval:org.mitre.oval:def:5832"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e0a5b.shtml" xml:lang="en">20070213 Multiple IOS IPS Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.cisco.com/en/US/products/products_security_response09186a00807e0a5e.html" xml:lang="en">http://www.cisco.com/en/US/products/products_security_response09186a00807e0a5e.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22549" xml:lang="en">22549</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017631" xml:lang="en">1017631</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0597" xml:lang="en">ADV-2007-0597</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32474" xml:lang="en">cisco-ios-ips-dos(32474)</vuln:reference>
    </vuln:references>
    <vuln:summary>The ATOMIC.TCP signature engine in the Intrusion Prevention System (IPS) feature for Cisco IOS 12.4XA, 12.3YA, 12.3T, and other trains allows remote attackers to cause a denial of service (IPS crash and traffic loss) via unspecified manipulations that are not properly handled by the regular expression feature, as demonstrated using the 3123.0 (Netbus Pro Traffic) signature.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0919">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nickolas_grigoriadis:mini_web_server:0.0.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nickolas_grigoriadis:mini_web_server:0.0.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0919</vuln:cve-id>
    <vuln:published-datetime>2007-02-14T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:29.907-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://attrition.org/pipermail/vim/2007-February/001315.html" xml:lang="en">20060213 Verified: dot in Miniwebsvr 0.0.6</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2248" xml:lang="en">2248</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459829/100/0/threaded" xml:lang="en">20070211 Miniwebsvr 0.0.6 - Directory traversal</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22523" xml:lang="en">22523</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32451" xml:lang="en">miniwebsvr-unspecified-directory-traversal(32451)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in Nickolas Grigoriadis Mini Web server (MiniWebsvr) 0.0.6 allows remote attackers to list the directory immediately above the web root via a ..%00 sequence in the URI.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0920">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:philboard:philboard:1.14"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:philboard:philboard:1.14</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0920</vuln:cve-id>
    <vuln:published-datetime>2007-02-14T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:06.333-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22532" xml:lang="en">22532</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0600" xml:lang="en">ADV-2007-0600</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32442" xml:lang="en">philboard-philboardforum-sql-injection(32442)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3295" xml:lang="en">3295</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in philboard_forum.asp in Philboard 1.14 and earlier allows remote attackers to execute arbitrary SQL commands via the forumid parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0921">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:radical_technologies:portal_search"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:radical_technologies:portal_search</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0921</vuln:cve-id>
    <vuln:published-datetime>2007-02-14T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:30.157-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2247" xml:lang="en">2247</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459794/100/0/threaded" xml:lang="en">20070212 Radical Technologies - Portal Search- multiple XSS issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22533" xml:lang="en">22533</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32460" xml:lang="en">portalsearch-frame-url-spoofing(32460)</vuln:reference>
    </vuln:references>
    <vuln:summary>Portal Search allows remote attackers to redirect a URL to an arbitrary web site by placing the URL in the query string to the top-level URI.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0922">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:radical_technologies:portal_search"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:radical_technologies:portal_search</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0922</vuln:cve-id>
    <vuln:published-datetime>2007-02-14T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:30.373-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2247" xml:lang="en">2247</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459794/100/0/threaded" xml:lang="en">20070212 Radical Technologies - Portal Search- multiple XSS issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22533" xml:lang="en">22533</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in buscador/buscador.htm in Portal Search allows remote attackers to inject arbitrary web script or HTML via the query string.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0923">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:radical_technologies:portal_search"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:radical_technologies:portal_search</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0923</vuln:cve-id>
    <vuln:published-datetime>2007-02-14T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:30.530-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2247" xml:lang="en">2247</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459794/100/0/threaded" xml:lang="en">20070212 Radical Technologies - Portal Search- multiple XSS issue</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22533" xml:lang="en">22533</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32452" xml:lang="en">portalsearch-buscador-info-disclosure(32452)</vuln:reference>
    </vuln:references>
    <vuln:summary>buscador/buscador.htm in Portal Search allows remote attackers to obtain sensitive information (business logic) via a query string composed of a search for certain characters.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0924">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:till_gerken:phppolls:1.0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:till_gerken:phppolls:1.0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0924</vuln:cve-id>
    <vuln:published-datetime>2007-02-14T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:30.750-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2242" xml:lang="en">2242</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459789/100/0/threaded" xml:lang="en">20070211 phpPolls 1.0.3 (acces to sensitive file)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22522" xml:lang="en">22522</vuln:reference>
    </vuln:references>
    <vuln:summary>Till Gerken phpPolls 1.0.3 allows remote attackers to bypass authentication and perform certain administrative actions via a direct request to phpPollAdmin.php3.  NOTE: this issue might subsume CVE-2006-3764.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0925">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:communityserver.org:community_server"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:communityserver.org:community_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0925</vuln:cve-id>
    <vuln:published-datetime>2007-02-14T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:30.907-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2241" xml:lang="en">2241</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459848/100/0/threaded" xml:lang="en">20070209 XSS in communityserver !</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22529" xml:lang="en">22529</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32444" xml:lang="en">communityserver-searchresults-xss(32444)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in search/SearchResults.aspx in Community Server allows remote attackers to inject arbitrary web script or HTML via the q parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0926">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:kvguestbook:kvguestbook:1.0_beta"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kvguestbook:kvguestbook:1.0_beta</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0926</vuln:cve-id>
    <vuln:published-datetime>2007-02-14T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:31.123-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2246" xml:lang="en">2246</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459799/100/0/threaded" xml:lang="en">20070211 KvGuestbook Remote Add Admin Exploit</vuln:reference>
    </vuln:references>
    <vuln:summary>The dologin function in guestbook.php in KvGuestbook 1.0 Beta allows remote attackers to gain administrative privileges, probably via modified $mysql['pass'] and $gbpass variables.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0927">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:utorrent:utorrent:1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:utorrent:utorrent:1.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0927</vuln:cve-id>
    <vuln:published-datetime>2007-02-14T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:31.250-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460346/100/0/threaded" xml:lang="en">20070216 utorrent issue?</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22530" xml:lang="en">22530</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017648" xml:lang="en">1017648</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0571" xml:lang="en">ADV-2007-0571</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32455" xml:lang="en">utorrent-torrent-bo(32455)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3296" xml:lang="en">3296</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in uTorrent 1.6 allows remote attackers to execute arbitrary code via a torrent file with a crafted announce header.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0928">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:virtual_calendar:virtual_calendar"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:virtual_calendar:virtual_calendar</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0928</vuln:cve-id>
    <vuln:published-datetime>2007-02-14T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:31.857-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2240" xml:lang="en">2240</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459844/100/0/threaded" xml:lang="en">20070210 Virtual Calendar &lt;= (pwd.txt) Remote Password Disclosur Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32446" xml:lang="en">virtualcalendar-pwd-information-disclosure(32446)</vuln:reference>
    </vuln:references>
    <vuln:summary>Virtual Calendar stores sensitive information under the web root with insufficient access control, which allows remote attackers to download an encoded password via a direct request for pwd.txt.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0929">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:guillaume_fontaine:php_rrd_browser:0.2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:guillaume_fontaine:php_rrd_browser:0.2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0929</vuln:cve-id>
    <vuln:published-datetime>2007-02-14T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:32.107-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://attrition.org/pipermail/vim/2007-February/001307.html" xml:lang="en">20070213 true: [Full-disclosure] Arbitrary file disclosure vulnerability in php rrd browser &lt; 0.2.1 (prb)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2245" xml:lang="en">2245</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?group_id=176562&amp;release_id=485414" xml:lang="en">http://sourceforge.net/project/shownotes.php?group_id=176562&amp;release_id=485414</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459804/100/0/threaded" xml:lang="en">20070211 Arbitrary file disclosure vulnerability in php rrd browser &lt; 0.2.1 (prb)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32425" xml:lang="en">prb-p-directory-traversal(32425)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in php rrd browser before 0.2.1 allows remote attackers to read arbitrary files via ".." sequences in the p parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0930">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apache_stats:apache_stats:0.0.1_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:apache_stats:apache_stats:0.0.2_beta"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache_stats:apache_stats:0.0.1_beta</vuln:product>
      <vuln:product>cpe:/a:apache_stats:apache_stats:0.0.2_beta</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0930</vuln:cve-id>
    <vuln:published-datetime>2007-02-14T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:50:58.970-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/forum/forum.php?forum_id=660919" xml:lang="en">http://sourceforge.net/forum/forum.php?forum_id=660919</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22388" xml:lang="en">22388</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0559" xml:lang="en">ADV-2007-0559</vuln:reference>
    </vuln:references>
    <vuln:summary>Variable extract vulnerability in Apache Stats before 0.0.3beta allows attackers to modify arbitrary variables and conduct attacks via unknown vectors involving the use of PHP's extract function.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0931">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:alcatel-lucent:omniaccess_wireless:43xx"/>
        <cpe-lang:fact-ref name="cpe:/h:alcatel-lucent:omniaccess_wireless:6000"/>
        <cpe-lang:fact-ref name="cpe:/h:aruba:mobility_controller:200"/>
        <cpe-lang:fact-ref name="cpe:/h:aruba:mobility_controller:800"/>
        <cpe-lang:fact-ref name="cpe:/h:aruba:mobility_controller:2400"/>
        <cpe-lang:fact-ref name="cpe:/h:aruba:mobility_controller:6000"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:alcatel-lucent:omniaccess_wireless:43xx</vuln:product>
      <vuln:product>cpe:/h:alcatel-lucent:omniaccess_wireless:6000</vuln:product>
      <vuln:product>cpe:/h:aruba:mobility_controller:200</vuln:product>
      <vuln:product>cpe:/h:aruba:mobility_controller:800</vuln:product>
      <vuln:product>cpe:/h:aruba:mobility_controller:2400</vuln:product>
      <vuln:product>cpe:/h:aruba:mobility_controller:6000</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0931</vuln:cve-id>
    <vuln:published-datetime>2007-02-14T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:32.390-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052380.html" xml:lang="en">20070213 Aruba Mobility Controller Management Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2244" xml:lang="en">2244</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/319913" xml:lang="en">VU#319913</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459928/100/0/threaded" xml:lang="en">20070213 Aruba Mobility Controller Management Buffer Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22538" xml:lang="en">22538</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32459" xml:lang="en">aruba-management-interface-bo(32459)</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in the management interfaces in (1) Aruba Mobility Controllers 200, 800, 2400, and 6000 and (2) Alcatel-Lucent OmniAccess Wireless 43xx and 6000 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via long credential strings.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0932">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:alcatel-lucent:omniaccess_wireless:43xx"/>
        <cpe-lang:fact-ref name="cpe:/h:alcatel-lucent:omniaccess_wireless:6000"/>
        <cpe-lang:fact-ref name="cpe:/h:aruba:mobility_controller:200"/>
        <cpe-lang:fact-ref name="cpe:/h:aruba:mobility_controller:800"/>
        <cpe-lang:fact-ref name="cpe:/h:aruba:mobility_controller:2400"/>
        <cpe-lang:fact-ref name="cpe:/h:aruba:mobility_controller:6000"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:alcatel-lucent:omniaccess_wireless:43xx</vuln:product>
      <vuln:product>cpe:/h:alcatel-lucent:omniaccess_wireless:6000</vuln:product>
      <vuln:product>cpe:/h:aruba:mobility_controller:200</vuln:product>
      <vuln:product>cpe:/h:aruba:mobility_controller:800</vuln:product>
      <vuln:product>cpe:/h:aruba:mobility_controller:2400</vuln:product>
      <vuln:product>cpe:/h:aruba:mobility_controller:6000</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0932</vuln:cve-id>
    <vuln:published-datetime>2007-02-14T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:32.857-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052382.html" xml:lang="en">20070213 Aruba Networks - Unauthorized Administrative and WLAN Access through Guest Account</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2243" xml:lang="en">2243</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/613833" xml:lang="en">VU#613833</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459927/100/0/threaded" xml:lang="en">20070213 Aruba Networks - Unauthorized Administrative and WLAN Access through Guest Account</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22538" xml:lang="en">22538</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32461" xml:lang="en">aruba-guestaccount-privilege-escalation(32461)</vuln:reference>
    </vuln:references>
    <vuln:summary>The (1) Aruba Mobility Controllers 200, 600, 2400, and 6000 and (2) Alcatel-Lucent OmniAccess Wireless 43xx and 6000 do not properly implement authentication and privilege assignment for the guest account, which allows remote attackers to access administrative interfaces or the WLAN.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0933">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/h:d-link:dwl-g650%2b:firmware_6.0.0.18"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0933</vuln:cve-id>
    <vuln:published-datetime>2007-06-05T17:30:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:30.860-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.blackhat.com/presentations/bh-europe-07/Butti/Presentation/bh-eu-07-Butti.pdf" xml:lang="en">http://www.blackhat.com/presentations/bh-europe-07/Butti/Presentation/bh-eu-07-Butti.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/24438" xml:lang="en">24438</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/34831" xml:lang="en">dlink-tim-information-bo(34831)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the wireless driver 6.0.0.18 for D-Link DWL-G650+ (Rev. A1) on Windows XP allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a beacon frame with a long TIM Information Element.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0934">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visio:2002"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:visio:2002</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0934</vuln:cve-id>
    <vuln:published-datetime>2007-06-12T15:30:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:33.407-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1925" name="oval:org.mitre.oval:def:1925"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/471947/100/0/threaded" xml:lang="en">SSRT071438</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/24349" xml:lang="en">24349</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018227" xml:lang="en">1018227</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-163A.html" xml:lang="en">TA07-163A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2150" xml:lang="en">ADV-2007-2150</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-030" xml:lang="en">MS07-030</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/34607" xml:lang="en">visio-version-code-execution(34607)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Microsoft Visio 2002 allows remote user-assisted attackers to execute arbitrary code via a Visio (.VSD, VSS, .VST) file with a crafted version number that triggers memory corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0935">
    <vuln:cve-id>CVE-2007-0935</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:05.603-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:05.603-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2007. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0936">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visio:2002:sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:visio:2002:sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0936</vuln:cve-id>
    <vuln:published-datetime>2007-06-12T15:30:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:34.140-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1369" name="oval:org.mitre.oval:def:1369"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/471947/100/0/threaded" xml:lang="en">SSRT071438</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/24384" xml:lang="en">24384</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018227" xml:lang="en">1018227</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-163A.html" xml:lang="en">TA07-163A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2150" xml:lang="en">ADV-2007-2150</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-030" xml:lang="en">MS07-030</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple unspecified vulnerabilities in Microsoft Visio 2002 allow remote user-assisted attackers to execute arbitrary code via a Visio (.VSD, VSS, .VST) file with a crafted packed object that triggers memory corruption, aka "Visio Document Packaging Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0937">
    <vuln:cve-id>CVE-2007-0937</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:05.637-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:05.637-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2007. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0938">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:content_management_server:2001:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:content_management_server:2002:sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:content_management_server:2001:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:content_management_server:2002:sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0938</vuln:cve-id>
    <vuln:published-datetime>2007-04-10T17:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:34.797-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2001" name="oval:org.mitre.oval:def:2001"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/434137" xml:lang="en">VU#434137</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/466331/100/200/threaded" xml:lang="en">HPSBST02208</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22861" xml:lang="en">22861</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017894" xml:lang="en">1017894</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1322" xml:lang="en">ADV-2007-1322</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-018" xml:lang="en">MS07-018</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32736" xml:lang="en">mcms-http-get-code-execution(32736)</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2 does not properly handle certain characters in a crafted HTTP GET request, which allows remote attackers to execute arbitrary code, aka the "CMS Memory Corruption Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0939">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:content_management_server:2001:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:content_management_server:2002:sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:content_management_server:2001:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:content_management_server:2002:sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0939</vuln:cve-id>
    <vuln:published-datetime>2007-04-10T17:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:35.607-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1575" name="oval:org.mitre.oval:def:1575"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/466331/100/200/threaded" xml:lang="en">HPSBST02208</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22860" xml:lang="en">22860</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017894" xml:lang="en">1017894</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1322" xml:lang="en">ADV-2007-1322</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-018" xml:lang="en">MS07-018</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving HTML redirection queries, aka "Cross-site Scripting and Spoofing Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0940">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:biztalk_server:2004:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:biztalk_server:2004:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:capicom"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:biztalk_server:2004:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:biztalk_server:2004:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:capicom</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0940</vuln:cve-id>
    <vuln:published-datetime>2007-05-08T19:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:36.250-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1670" name="oval:org.mitre.oval:def:1670"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/866305" xml:lang="en">VU#866305</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/468871/100/200/threaded" xml:lang="en">HPSBST02214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23782" xml:lang="en">23782</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018016" xml:lang="en">1018016</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018017" xml:lang="en">1018017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" xml:lang="en">TA07-128A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1713" xml:lang="en">ADV-2007-1713</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-028" xml:lang="en">MS07-028</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32739" xml:lang="en">ms-capicom-code-execution(32739)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the Cryptographic API Component Object Model Certificates ActiveX control (CAPICOM.dll) in Microsoft CAPICOM and BizTalk Server 2004 SP1 and SP2 allows remote attackers to execute arbitrary code via unspecified vectors, aka the "CAPICOM.Certificates Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0941">
    <vuln:cve-id>CVE-2007-0941</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:05.667-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:05.667-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2007. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0942">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0.1:sp4"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1::itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp2::itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp2::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional_x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1::itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp2::itanium"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp2::x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::gold:x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional_x64"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.0.1:sp4</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:7.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0942</vuln:cve-id>
    <vuln:published-datetime>2007-05-08T19:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:37.280-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1939" name="oval:org.mitre.oval:def:1939"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/468871/100/200/threaded" xml:lang="en">HPSBST02214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018019" xml:lang="en">1018019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" xml:lang="en">TA07-128A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1712" xml:lang="en">ADV-2007-1712</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-027" xml:lang="en">MS07-027</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33252" xml:lang="en">ie-chtskdic-com-code-execution(33252)</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4; 6 SP1 on Windows 2000 SP4; 6 and 7 on Windows XP SP2, or Windows Server 2003 SP1 or SP2; and possibly 7 on Windows Vista does not properly "instantiate certain COM objects as ActiveX controls," which allows remote attackers to execute arbitrary code via a crafted COM object from chtskdic.dll.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0943">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.01"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.01</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0943</vuln:cve-id>
    <vuln:published-datetime>2007-08-14T17:17:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:42:55.313-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1673" name="oval:org.mitre.oval:def:1673"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1018562" xml:lang="en">1018562</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.nsfocus.com/english/homepage/research/0701.htm" xml:lang="en">http://www.nsfocus.com/english/homepage/research/0701.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/25288" xml:lang="en">25288</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-226A.html" xml:lang="en">TA07-226A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2869" xml:lang="en">ADV-2007-2869</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-045" xml:lang="en">MS07-045</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Internet Explorer 5.01 and 6 SP1 allows remote attackers to execute arbitrary code via crafted Cascading Style Sheets (CSS) strings that trigger memory corruption during parsing, related to use of out-of-bounds pointers.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0944">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.01:sp4"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.01:sp4</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0944</vuln:cve-id>
    <vuln:published-datetime>2007-05-08T19:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:38.297-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1722" name="oval:org.mitre.oval:def:1722"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/467989/100/0/threaded" xml:lang="en">20070508 ZDI-07-027: Microsoft Internet Explorer Table Column Deletion Memory Corruption Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/468871/100/200/threaded" xml:lang="en">HPSBST02214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23771" xml:lang="en">23771</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018019" xml:lang="en">1018019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" xml:lang="en">TA07-128A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1712" xml:lang="en">ADV-2007-1712</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-07-027.html" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-07-027.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-027" xml:lang="en">MS07-027</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33253" xml:lang="en">ie-object-array-code-execution(33253)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the CTableCol::OnPropertyChange method in Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4; 6 SP1 on Windows 2000 SP4; and 6 on Windows XP SP2, or Windows Server 2003 SP1 or SP2 allows remote attackers to execute arbitrary code by calling deleteCell on a named table row in a named table column, then accessing the column, which causes Internet Explorer to access previously deleted objects, aka the "Uninitialized Memory Corruption Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0945">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6:sp1"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:6:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:7.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0945</vuln:cve-id>
    <vuln:published-datetime>2007-05-08T19:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:39.797-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1463" name="oval:org.mitre.oval:def:1463"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/468871/100/200/threaded" xml:lang="en">HPSBST02214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23769" xml:lang="en">23769</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018019" xml:lang="en">1018019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" xml:lang="en">TA07-128A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1712" xml:lang="en">ADV-2007-1712</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-027" xml:lang="en">MS07-027</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Internet Explorer 6 SP1 on Windows 2000 SP4; 6 and 7 on Windows XP SP2, or Windows Server 2003 SP1 or SP2; and 7 on Windows Vista allows remote attackers to execute arbitrary code via certain property methods that may trigger memory corruption, aka "Property Memory Corruption Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0946">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:7.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0946</vuln:cve-id>
    <vuln:published-datetime>2007-05-08T19:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:40.623-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1441" name="oval:org.mitre.oval:def:1441"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/468871/100/200/threaded" xml:lang="en">HPSBST02214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23770" xml:lang="en">23770</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018019" xml:lang="en">1018019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" xml:lang="en">TA07-128A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1712" xml:lang="en">ADV-2007-1712</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-027" xml:lang="en">MS07-027</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33255" xml:lang="en">ie-html-memory-code-execution(33255)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Microsoft Internet Explorer 7 on Windows XP SP2, Windows Server 2003 SP1 or SP2, or Windows Vista allows remote attackers to execute arbitrary code via crafted HTML objects, which results in memory corruption, aka the first of two "HTML Objects Memory Corruption Vulnerabilities" and a different issue than CVE-2007-0947.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0947">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:6</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:7.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0947</vuln:cve-id>
    <vuln:published-datetime>2007-05-08T19:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:41.390-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2048" name="oval:org.mitre.oval:def:2048"/>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/468871/100/200/threaded" xml:lang="en">HPSBST02214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23772" xml:lang="en">23772</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018019" xml:lang="en">1018019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" xml:lang="en">TA07-128A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1712" xml:lang="en">ADV-2007-1712</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-027" xml:lang="en">MS07-027</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33256" xml:lang="en">ie-html-memory-code-execution-variant(33256)</vuln:reference>
    </vuln:references>
    <vuln:summary>Use-after-free vulnerability in Microsoft Internet Explorer 7 on Windows XP SP2, Windows Server 2003 SP1 or SP2, or Windows Vista allows remote attackers to execute arbitrary code via crafted HTML objects, resulting in accessing deallocated memory of CMarkup objects, aka the second of two "HTML Objects Memory Corruption Vulnerabilities" and a different issue than CVE-2007-0946.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0948">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:virtual_pc:6.1::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:virtual_pc:7::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:virtual_pc:2004"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:virtual_server:2005"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:virtual_server:2005:r2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:virtual_pc:6.1::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:virtual_pc:7::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:virtual_pc:2004</vuln:product>
      <vuln:product>cpe:/a:microsoft:virtual_server:2005</vuln:product>
      <vuln:product>cpe:/a:microsoft:virtual_server:2005:r2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0948</vuln:cve-id>
    <vuln:published-datetime>2007-08-14T18:17:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:43:01.893-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1259" name="oval:org.mitre.oval:def:1259"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/25298" xml:lang="en">25298</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018567" xml:lang="en">1018567</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-226A.html" xml:lang="en">TA07-226A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2873" xml:lang="en">ADV-2007-2873</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-049" xml:lang="en">MS07-049</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in Microsoft Virtual PC 2004 and PC for Mac 7.1 and 7, and Virtual Server 2005 and 2005 R2, allows local guest OS administrators to execute arbitrary code on the host OS via unspecified vectors related to "interaction and initialization of components."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0949">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:itinysoft_studio:total_video_player:1.03"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:itinysoft_studio:total_video_player:1.03</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0949</vuln:cve-id>
    <vuln:published-datetime>2007-02-14T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:41.797-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22553" xml:lang="en">22553</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32479" xml:lang="en">totalvideoplayer-m3u-bo(32479)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/5032" xml:lang="en">5032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/5077" xml:lang="en">5077</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in iTinySoft Studio Total Video Player 1.03, and possibly earlier, allows remote attackers to execute arbitrary code via a M3U playlist file that contains a long file name. NOTE: it was later reported that 1.20 and 1.30 are also affected.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0950">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:fullaspsite:asp_hosting_site"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:fullaspsite:asp_hosting_site</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0950</vuln:cve-id>
    <vuln:published-datetime>2007-02-14T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:42.297-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2250" xml:lang="en">2250</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459979/100/0/threaded" xml:lang="en">20070213 Fullaspsite Shop (tr) Xss &amp; SqL &amp;#304;nj. VulnZ.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22545" xml:lang="en">22545</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32469" xml:lang="en">fullaspsite-listmain-xss(32469)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in listmain.asp in Fullaspsite ASP Hosting Site allows remote attackers to inject arbitrary web script or HTML via the cat parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0951">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:fullaspsite:asp_hosting_site"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:fullaspsite:asp_hosting_site</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0951</vuln:cve-id>
    <vuln:published-datetime>2007-02-14T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:42.560-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2250" xml:lang="en">2250</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459979/100/0/threaded" xml:lang="en">20070213 Fullaspsite Shop (tr) Xss &amp; SqL &amp;#304;nj. VulnZ.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22545" xml:lang="en">22545</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32470" xml:lang="en">fullaspsite-listmain-sql-injection(32470)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in listmain.asp in Fullaspsite ASP Hosting Site allows remote attackers to execute arbitrary SQL commands via the cat parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0952">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:scriptsez.net:virtual_calendar"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:scriptsez.net:virtual_calendar</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0952</vuln:cve-id>
    <vuln:published-datetime>2007-02-14T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:31.547-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22536" xml:lang="en">22536</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32448" xml:lang="en">virtualcalendar-unspecified-xss(32448)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Scriptsez.net Virtual Calendar allow remote attackers to inject arbitrary web script or HTML via the (1) t and (2) yr parameters, and the (3) sho parameter when the m parameter is outside the intended range.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0953">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:atmail:atmail_webmail:4.3::windows"/>
        <cpe-lang:fact-ref name="cpe:/a:atmail:atmail_webmail:4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:atmail:atmail_webmail:4.11::freebsd"/>
        <cpe-lang:fact-ref name="cpe:/a:atmail:atmail_webmail:4.11::hp-ux"/>
        <cpe-lang:fact-ref name="cpe:/a:atmail:atmail_webmail:4.11::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:atmail:atmail_webmail:4.11::mac_os_x"/>
        <cpe-lang:fact-ref name="cpe:/a:atmail:atmail_webmail:4.11::solaris"/>
        <cpe-lang:fact-ref name="cpe:/a:atmail:atmail_webmail:4.51"/>
        <cpe-lang:fact-ref name="cpe:/a:atmail:atmail_webmail:4.61"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:atmail:atmail_webmail:4.3::windows</vuln:product>
      <vuln:product>cpe:/a:atmail:atmail_webmail:4.6</vuln:product>
      <vuln:product>cpe:/a:atmail:atmail_webmail:4.11::freebsd</vuln:product>
      <vuln:product>cpe:/a:atmail:atmail_webmail:4.11::hp-ux</vuln:product>
      <vuln:product>cpe:/a:atmail:atmail_webmail:4.11::linux</vuln:product>
      <vuln:product>cpe:/a:atmail:atmail_webmail:4.11::mac_os_x</vuln:product>
      <vuln:product>cpe:/a:atmail:atmail_webmail:4.11::solaris</vuln:product>
      <vuln:product>cpe:/a:atmail:atmail_webmail:4.51</vuln:product>
      <vuln:product>cpe:/a:atmail:atmail_webmail:4.61</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0953</vuln:cve-id>
    <vuln:published-datetime>2007-02-14T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:31.593-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://kb.atmail.com/?p=410" xml:lang="en">http://kb.atmail.com/?p=410</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://lostmon.blogspot.com/2007/02/mail-searchpl-keywords-variable-cross.html" xml:lang="en">http://lostmon.blogspot.com/2007/02/mail-searchpl-keywords-variable-cross.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22552" xml:lang="en">22552</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0603" xml:lang="en">ADV-2007-0603</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32483" xml:lang="en">@mail-search-xss(32483)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in search.pl in @Mail 4.61 and earlier allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0954">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mohachat:moha_chat:0.1b7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mohachat:moha_chat:0.1b7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0954</vuln:cve-id>
    <vuln:published-datetime>2007-02-14T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:51:01.783-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://mohachat.sourceforge.net/download/release_notes/#0.1b8" xml:lang="en">http://mohachat.sourceforge.net/download/release_notes/#0.1b8</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0599" xml:lang="en">ADV-2007-0599</vuln:reference>
    </vuln:references>
    <vuln:summary>MOHA Chat 0.1b7 and earlier does not require authentication for use of the plug in API, which has unknown impact and attack vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0955">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable:2.35::~~professional~~~"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mailenable:mailenable:2.35::~~professional~~~</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0955</vuln:cve-id>
    <vuln:published-datetime>2007-02-14T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-10-02T16:13:21.207-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2019-10-01T12:33:51.887-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0321.html" xml:lang="en">20070214 MailEnable DoS POC</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0333.html" xml:lang="en">20070214 MailEnable DoS POC-2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052427.html" xml:lang="en">20071214 MailEnable DoS POC</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2249" xml:lang="en">2249</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0614" xml:lang="en">ADV-2007-0614</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32482" xml:lang="en">mailenable-ntlm-dos(32482)</vuln:reference>
    </vuln:references>
    <vuln:summary>The NTLM_UnPack_Type3 function in MENTLM.dll in MailEnable Professional 2.35 and earlier allows remote attackers to cause a denial of service (application crash) via certain base64-encoded data following an AUTHENTICATE NTLM command to the imap port (143/tcp), which results in an out-of-bounds read.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0956">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:rpath:linux:1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mit:kerberos:5-1.6</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.1</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:4.0</vuln:product>
      <vuln:product>cpe:/o:rpath:linux:1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0956</vuln:cve-id>
    <vuln:published-datetime>2007-04-05T21:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:42.843-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10046" name="oval:org.mitre.oval:def:10046"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070401-01-P.asc" xml:lang="en">20070401-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Apr/0001.html" xml:lang="en">SUSE-SA:2007:025</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200704-02.xml" xml:lang="en">GLSA-200704-02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102867-1" xml:lang="en">102867</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2007-001-telnetd.txt" xml:lang="en">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2007-001-telnetd.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1276" xml:lang="en">DSA-1276</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/220816" xml:lang="en">VU#220816</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:077" xml:lang="en">MDKSA-2007:077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0095.html" xml:lang="en">RHSA-2007:0095</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/464590/100/0/threaded" xml:lang="en">20070403 MITKRB5-SA-2007-001: telnetd allows login as arbitrary user [CVE-2007-0956]</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/464666/100/0/threaded" xml:lang="en">20070404 rPSA-2007-0063-1 krb5 krb5-server krb5-services krb5-test krb5-workstation</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/464814/30/7170/threaded" xml:lang="en">20070405 FLEA-2007-0008-1: krb5</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23281" xml:lang="en">23281</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017848" xml:lang="en">1017848</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-449-1" xml:lang="en">USN-449-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-093B.html" xml:lang="en">TA07-093B</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1218" xml:lang="en">ADV-2007-1218</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1249" xml:lang="en">ADV-2007-1249</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33414" xml:lang="en">kerberos-telnet-security-bypass(33414)</vuln:reference>
    </vuln:references>
    <vuln:summary>The telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote attackers to bypass authentication and gain system access via a username beginning with a '-' character, a similar issue to CVE-2007-0882.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0957">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mit:kerberos:5-1.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0957</vuln:cve-id>
    <vuln:published-datetime>2007-04-05T21:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:45.140-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10757" name="oval:org.mitre.oval:def:10757"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070401-01-P.asc" xml:lang="en">20070401-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305391" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305391</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" xml:lang="en">APPLE-SA-2007-04-19</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Apr/0001.html" xml:lang="en">SUSE-SA:2007:025</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200704-02.xml" xml:lang="en">GLSA-200704-02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102930-1" xml:lang="en">102930</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2007-002-syslog.txt" xml:lang="en">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2007-002-syslog.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1276" xml:lang="en">DSA-1276</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/704024" xml:lang="en">VU#704024</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:077" xml:lang="en">MDKSA-2007:077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0095.html" xml:lang="en">RHSA-2007:0095</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/464592/100/0/threaded" xml:lang="en">20070403 MITKRB5-SA-2007-002: KDC, kadmind stack overflow in krb5_klog_syslog [CVE-2007-0957]</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/464666/100/0/threaded" xml:lang="en">20070404 rPSA-2007-0063-1 krb5 krb5-server krb5-services krb5-test krb5-workstation</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/464814/30/7170/threaded" xml:lang="en">20070405 FLEA-2007-0008-1: krb5</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23285" xml:lang="en">23285</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017849" xml:lang="en">1017849</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-449-1" xml:lang="en">USN-449-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-093B.html" xml:lang="en">TA07-093B</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" xml:lang="en">TA07-109A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1218" xml:lang="en">ADV-2007-1218</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1250" xml:lang="en">ADV-2007-1250</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1470" xml:lang="en">ADV-2007-1470</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1983" xml:lang="en">ADV-2007-1983</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33411" xml:lang="en">kerberos-krb5klogsyslog-bo(33411)</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in the krb5_klog_syslog function in the kadm5 library, as used by the Kerberos administration daemon (kadmind) and Key Distribution Center (KDC), in MIT krb5 before 1.6.1 allows remote authenticated users to execute arbitrary code and modify the Kerberos key database via crafted arguments, possibly involving certain format string specifiers.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0958">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.8.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.9:2.6.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.25"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.26"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.28"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.29"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.30"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.31"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.32"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.33"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.34"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.35"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.36"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.37"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.38"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.39"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.40"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.41"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.8.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.9:2.6.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.25</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.26</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.28</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.29</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.30</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.31</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.32</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.33</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.34</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.35</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.36</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.37</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.38</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.39</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.40</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.41</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0958</vuln:cve-id>
    <vuln:published-datetime>2007-02-15T13:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:10.013-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10343" name="oval:org.mitre.oval:def:10343"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2007-0488.html" xml:lang="en">RHSA-2007:0488</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2007-287.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2007-287.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1286" xml:lang="en">DSA-1286</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1304" xml:lang="en">DSA-1304</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.isec.pl/vulnerabilities/isec-0017-binfmt_elf.txt" xml:lang="en">http://www.isec.pl/vulnerabilities/isec-0017-binfmt_elf.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20" xml:lang="en">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:060" xml:lang="en">MDKSA-2007:060</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:078" xml:lang="en">MDKSA-2007:078</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0099.html" xml:lang="en">RHSA-2007:0099</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22903" xml:lang="en">22903</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-451-1" xml:lang="en">USN-451-1</vuln:reference>
    </vuln:references>
    <vuln:summary>Linux kernel 2.6.x before 2.6.20 allows local users to read unreadable binaries by using the interpreter (PT_INTERP) functionality and triggering a core dump, a variant of CVE-2004-1073.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0959">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:cisco:asa_5500:7.2%282%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:7.2%282%29"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:cisco:asa_5500:7.2%282%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:7.2%282%29</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0959</vuln:cve-id>
    <vuln:published-datetime>2007-02-15T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:27.717-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2484.shtml" xml:lang="en">20070214 Multiple Vulnerabilities in Cisco PIX and ASA Appliances</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22561" xml:lang="en">22561</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22562" xml:lang="en">22562</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017651" xml:lang="en">1017651</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017652" xml:lang="en">1017652</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0608" xml:lang="en">ADV-2007-0608</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32488" xml:lang="en">cisco-pix-asa-tcp-dos(32488)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cisco PIX 500 and ASA 5500 Series Security Appliances 7.2.2, when configured to inspect certain TCP-based protocols, allows remote attackers to cause a denial of service (device reboot) via malformed TCP packets.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0960">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:cisco:asa_5500:7.2%282%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:7.2%282%29"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:cisco:asa_5500:7.2%282%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:7.2%282%29</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0960</vuln:cve-id>
    <vuln:published-datetime>2007-02-15T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:27.717-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2484.shtml" xml:lang="en">20070214 Multiple Vulnerabilities in Cisco PIX and ASA Appliances</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22561" xml:lang="en">22561</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22562" xml:lang="en">22562</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017651" xml:lang="en">1017651</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017652" xml:lang="en">1017652</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0608" xml:lang="en">ADV-2007-0608</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32489" xml:lang="en">cisco-pix-asa-local-privilege-escalation(32489)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Cisco PIX 500 and ASA 5500 Series Security Appliances 7.2.2, when configured to use the LOCAL authentication method, allows remote authenticated users to gain privileges via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0961">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:cisco:asa_5500:6.3"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:asa_5500:7.0"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:asa_5500:7.1"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:asa_5500:7.2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:6.3"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:7.0"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:7.1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:7.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:cisco:asa_5500:6.3</vuln:product>
      <vuln:product>cpe:/h:cisco:asa_5500:7.0</vuln:product>
      <vuln:product>cpe:/h:cisco:asa_5500:7.1</vuln:product>
      <vuln:product>cpe:/h:cisco:asa_5500:7.2</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:6.3</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:7.0</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:7.1</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:7.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0961</vuln:cve-id>
    <vuln:published-datetime>2007-02-15T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:19.370-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017651" xml:lang="en">1017651</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2481.shtml" xml:lang="en">20070214 Multiple Vulnerabilities in Firewall Services Module</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2484.shtml" xml:lang="en">20070214 Multiple Vulnerabilities in Cisco PIX and ASA Appliances</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/430969" xml:lang="en">VU#430969</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22561" xml:lang="en">22561</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22562" xml:lang="en">22562</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017652" xml:lang="en">1017652</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0608" xml:lang="en">ADV-2007-0608</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32487" xml:lang="en">cisco-pix-asa-sip-dos(32487)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32501" xml:lang="en">cisco-fwsm-sip-dos(32501)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cisco PIX 500 and ASA 5500 Series Security Appliances 6.x before 6.3(5.115), 7.0 before 7.0(5.2), and 7.1 before 7.1(2.5), and the FWSM 3.x before 3.1(3.24), when the "inspect sip" option is enabled, allows remote attackers to cause a denial of service (device reboot) via malformed SIP packets.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0962">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:cisco:firewall_services_module:2.3"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:firewall_services_module:3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:cisco:asa_5500:7.0"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:asa_5500:7.1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:7.0"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall_software:7.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:cisco:asa_5500:7.0</vuln:product>
      <vuln:product>cpe:/h:cisco:asa_5500:7.1</vuln:product>
      <vuln:product>cpe:/h:cisco:firewall_services_module:2.3</vuln:product>
      <vuln:product>cpe:/h:cisco:firewall_services_module:3.1</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:7.0</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall_software:7.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0962</vuln:cve-id>
    <vuln:published-datetime>2007-02-15T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:19.340-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017651" xml:lang="en">1017651</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2481.shtml" xml:lang="en">20070214 Multiple Vulnerabilities in Firewall Services Module</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2484.shtml" xml:lang="en">20070214 Multiple Vulnerabilities in Cisco PIX and ASA Appliances</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22561" xml:lang="en">22561</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22562" xml:lang="en">22562</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017652" xml:lang="en">1017652</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0608" xml:lang="en">ADV-2007-0608</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32486" xml:lang="en">cisco-pix-asa-http-dos(32486)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cisco PIX 500 and ASA 5500 Series Security Appliances 7.0 before 7.0(4.14) and 7.1 before 7.1(2.1), and the FWSM 2.x before 2.3(4.12) and 3.x before 3.1(3.24), when "inspect http" is enabled, allows remote attackers to cause a denial of service (device reboot) via malformed HTTP traffic.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0963">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:cisco:firewall_services_module:3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:cisco:firewall_services_module:3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0963</vuln:cve-id>
    <vuln:published-datetime>2007-02-15T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:51:02.893-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2481.shtml" xml:lang="en">20070214 Multiple Vulnerabilities in Firewall Services Module</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22561" xml:lang="en">22561</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0609" xml:lang="en">ADV-2007-0609</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Cisco Firewall Services Module (FWSM) 3.x before 3.1(3.3), when set to log at the "debug" level, allows remote attackers to cause a denial of service (device reboot) by sending packets that are not of a particular protocol such as TCP or UDP, which triggers the reboot during generation of Syslog message 710006.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0964">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:cisco:firewall_services_module:3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:cisco:firewall_services_module:3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0964</vuln:cve-id>
    <vuln:published-datetime>2007-02-15T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:51:03.017-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2481.shtml" xml:lang="en">20070214 Multiple Vulnerabilities in Firewall Services Module</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22561" xml:lang="en">22561</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0609" xml:lang="en">ADV-2007-0609</vuln:reference>
    </vuln:references>
    <vuln:summary>Cisco FWSM 3.x before 3.1(3.18), when authentication is configured to use "aaa authentication match" or "aaa authentication include", allows remote attackers to cause a denial of service (device reboot) via a malformed HTTPS request.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0965">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:cisco:firewall_services_module:3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:cisco:firewall_services_module:3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0965</vuln:cve-id>
    <vuln:published-datetime>2007-02-15T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:51:03.127-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2481.shtml" xml:lang="en">20070214 Multiple Vulnerabilities in Firewall Services Module</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22561" xml:lang="en">22561</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0609" xml:lang="en">ADV-2007-0609</vuln:reference>
    </vuln:references>
    <vuln:summary>Cisco FWSM 3.x before 3.1(3.2), when authentication is configured to use "aaa authentication match" or "aaa authentication include", allows remote attackers to cause a denial of service (device reboot) via a long HTTP request.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0966">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:cisco:firewall_services_module:3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:cisco:firewall_services_module:3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0966</vuln:cve-id>
    <vuln:published-datetime>2007-02-15T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:32.187-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2481.shtml" xml:lang="en">20070214 Multiple Vulnerabilities in Firewall Services Module</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22561" xml:lang="en">22561</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0609" xml:lang="en">ADV-2007-0609</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32497" xml:lang="en">cisco-fwsm-http-dos(32497)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32513" xml:lang="en">cisco-fwsm-https-server-dos(32513)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cisco Firewall Services Module (FWSM) 3.x before 3.1(3.11), when the HTTPS server is enabled, allows remote attackers to cause a denial of service (device reboot) via certain HTTPS traffic.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0967">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:cisco:firewall_services_module:3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:cisco:firewall_services_module:3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0967</vuln:cve-id>
    <vuln:published-datetime>2007-02-15T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:32.237-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2481.shtml" xml:lang="en">20070214 Multiple Vulnerabilities in Firewall Services Module</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22561" xml:lang="en">22561</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0609" xml:lang="en">ADV-2007-0609</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32515" xml:lang="en">cisco-fwsm-snmp-dos(32515)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cisco Firewall Services Module (FWSM) 3.x before 3.1(3.1) allows remote attackers to cause a denial of service (device reboot) via malformed SNMP requests.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0968">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:cisco:firewall_services_module:2.3"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:firewall_services_module:3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:cisco:firewall_services_module:2.3</vuln:product>
      <vuln:product>cpe:/h:cisco:firewall_services_module:3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0968</vuln:cve-id>
    <vuln:published-datetime>2007-02-15T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:32.297-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2481.shtml" xml:lang="en">20070214 Multiple Vulnerabilities in Firewall Services Module</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22561" xml:lang="en">22561</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017650" xml:lang="en">1017650</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0609" xml:lang="en">ADV-2007-0609</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32521" xml:lang="en">cisco-fwsm-acl-security-bypass(32521)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Cisco Firewall Services Module (FWSM) before 2.3(4.7) and 3.x before 3.1(3.1) causes the access control entries (ACE) in an ACL to be improperly evaluated, which allows remote authenticated users to bypass intended certain ACL protections.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0969">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:webtester:webtester:5.0_2006-09-27"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:webtester:webtester:5.0_2006-09-27</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0969</vuln:cve-id>
    <vuln:published-datetime>2007-02-15T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:47.907-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2261" xml:lang="en">2261</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460078/100/0/threaded" xml:lang="en">20070214 WebTester 5.0.2 sql injection and XSS vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22559" xml:lang="en">22559</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0633" xml:lang="en">ADV-2007-0633</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32492" xml:lang="en">webtester-post-xss(32492)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in WebTester 5.0.20060927 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to POST parameters to multiple files.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0970">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:webtester:webtester:5.0_2006-09-27"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:webtester:webtester:5.0_2006-09-27</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0970</vuln:cve-id>
    <vuln:published-datetime>2007-02-15T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:48.233-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2261" xml:lang="en">2261</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460078/100/0/threaded" xml:lang="en">20070214 WebTester 5.0.2 sql injection and XSS vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22559" xml:lang="en">22559</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0633" xml:lang="en">ADV-2007-0633</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32490" xml:lang="en">webtester-directions-sql-injection(32490)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in WebTester 5.0.20060927 and earlier allow remote attackers to execute arbitrary SQL commands via the testID parameter to directions.php, and unspecified parameters to other files that accept GET or POST input.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0971">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:jupiter_cms:jupiter_cms:1.1.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:jupiter_cms:jupiter_cms:1.1.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0971</vuln:cve-id>
    <vuln:published-datetime>2007-02-15T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:48.640-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://mgsdl.free.fr/advisories/12070214.txt" xml:lang="en">http://mgsdl.free.fr/advisories/12070214.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.acid-root.new.fr/advisories/12070214.txt" xml:lang="en">http://www.acid-root.new.fr/advisories/12070214.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460076/100/0/threaded" xml:lang="en">20070214 Jupiter CMS 1.1.5 Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460100/100/0/threaded" xml:lang="en">20070214 Re: Jupiter CMS 1.1.5 Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22560" xml:lang="en">22560</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3310" xml:lang="en">3310</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in Jupiter CMS 1.1.5 allow remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header and certain other HTTP headers, which set the ip variable that is used in SQL queries performed by index.php and certain other PHP scripts.  NOTE: the attack vector might involve _SERVER.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0972">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:jupiter_cms:jupiter_cms:1.1.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:jupiter_cms:jupiter_cms:1.1.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0972</vuln:cve-id>
    <vuln:published-datetime>2007-02-15T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:49.170-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://mgsdl.free.fr/advisories/12070214.txt" xml:lang="en">http://mgsdl.free.fr/advisories/12070214.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.acid-root.new.fr/advisories/12070214.txt" xml:lang="en">http://www.acid-root.new.fr/advisories/12070214.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460076/100/0/threaded" xml:lang="en">20070214 Jupiter CMS 1.1.5 Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460100/100/0/threaded" xml:lang="en">20070214 Re: Jupiter CMS 1.1.5 Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22560" xml:lang="en">22560</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32517" xml:lang="en">jupitercm-emoticons-file-upload(32517)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3311" xml:lang="en">3311</vuln:reference>
    </vuln:references>
    <vuln:summary>Unrestricted file upload vulnerability in modules/emoticons.php in Jupiter CMS 1.1.5 allows remote attackers to upload arbitrary files by modifying the HTTP request to send an image content type, and to omit is_guest and is_user parameters.  NOTE: this issue might be related to CVE-2006-4875.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0973">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:jupiter_cms:jupiter_cms:1.1.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:jupiter_cms:jupiter_cms:1.1.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0973</vuln:cve-id>
    <vuln:published-datetime>2007-02-15T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:49.657-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://mgsdl.free.fr/advisories/12070214.txt" xml:lang="en">http://mgsdl.free.fr/advisories/12070214.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.acid-root.new.fr/advisories/12070214.txt" xml:lang="en">http://www.acid-root.new.fr/advisories/12070214.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460076/100/0/threaded" xml:lang="en">20070214 Jupiter CMS 1.1.5 Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460100/100/0/threaded" xml:lang="en">20070214 Re: Jupiter CMS 1.1.5 Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22560" xml:lang="en">22560</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32518" xml:lang="en">jupitercm-loggedguests-xss(32518)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in index.php in Jupiter CMS 1.1.5 allow remote attackers to inject arbitrary web script or HTML via the Referer HTTP header and certain other HTTP headers, which are displayed without proper sanitization when an administrator performs a Logged Guest action.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0974">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ian_bezanson:dropbox:0.0.3_beta"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ian_bezanson:dropbox:0.0.3_beta</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0974</vuln:cve-id>
    <vuln:published-datetime>2007-02-15T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:51:04.173-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/forum/forum.php?forum_id=660819" xml:lang="en">http://sourceforge.net/forum/forum.php?forum_id=660819</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0598" xml:lang="en">ADV-2007-0598</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple unspecified vulnerabilities in Ian Bezanson DropBox before 0.0.4 beta have unknown impact and attack vectors, possibly related to a variable extraction vulnerability.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0975">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apache_stats:apache_stats:0.0.1_beta"/>
        <cpe-lang:fact-ref name="cpe:/a:apache_stats:apache_stats:0.0.2_beta"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache_stats:apache_stats:0.0.1_beta</vuln:product>
      <vuln:product>cpe:/a:apache_stats:apache_stats:0.0.2_beta</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0975</vuln:cve-id>
    <vuln:published-datetime>2007-02-15T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:51:04.267-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/forum/forum.php?forum_id=660919" xml:lang="en">http://sourceforge.net/forum/forum.php?forum_id=660919</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://superb-east.dl.sourceforge.net/sourceforge/apachestats/apacheStats_0.0.3Beta.tar.bz2" xml:lang="en">http://superb-east.dl.sourceforge.net/sourceforge/apachestats/apacheStats_0.0.3Beta.tar.bz2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0598" xml:lang="en">ADV-2007-0598</vuln:reference>
    </vuln:references>
    <vuln:summary>Variable extraction vulnerability in Ian Bezanson Apache Stats before 0.0.3 beta allows attackers to overwrite critical variables, with unknown impact, when the extract function is used on the _REQUEST superglobal array.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0976">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:activex_soft:actsoft_dvd_tools:3.8.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:activex_soft:actsoft_dvd_tools:3.8.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0976</vuln:cve-id>
    <vuln:published-datetime>2007-02-15T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:42.127-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22558" xml:lang="en">22558</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.shinnai.altervista.org/moaxb/20070504/actsoft.txt" xml:lang="en">http://www.shinnai.altervista.org/moaxb/20070504/actsoft.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.shinnai.altervista.org/viewtopic.php?id=41&amp;t_id=30" xml:lang="en">http://www.shinnai.altervista.org/viewtopic.php?id=41&amp;t_id=30</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32529" xml:lang="en">dvdtools-dvdtools-bo(32529)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3307" xml:lang="en">3307</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3610" xml:lang="en">3610</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the ActSoft DVD-Tools ActiveX control (dvdtools.ocx) allows remote attackers to execute arbitrary code via a long DVD_TOOLS.OpenDVD property value.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0977">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:lotus_domino:5.0</vuln:product>
      <vuln:product>cpe:/a:ibm:lotus_domino:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0977</vuln:cve-id>
    <vuln:published-datetime>2007-02-15T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:42.190-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3302" xml:lang="en">3302</vuln:reference>
    </vuln:references>
    <vuln:summary>IBM Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores HTTPPassword hashes from names.nsf in a manner accessible through Readviewentries and OpenDocument requests to the defaultview view, a different vector than CVE-2005-2428.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0978">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:5.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:5.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0978</vuln:cve-id>
    <vuln:published-datetime>2007-02-15T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:32.627-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017656" xml:lang="en">1017656</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0617" xml:lang="en">ADV-2007-0617</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?uid=isg1IY94901" xml:lang="en">IY94901</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32508" xml:lang="en">aix-swcons-bo(32508)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in swcons in IBM AIX 5.3 allows local users to gain privileges via long input data.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0979">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:lifetype:lifetype:1.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:lifetype:lifetype:1.2_beta_1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:lifetype:lifetype:1.1.5</vuln:product>
      <vuln:product>cpe:/a:lifetype:lifetype:1.2_beta_1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0979</vuln:cve-id>
    <vuln:published-datetime>2007-02-15T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:51:04.610-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.lifetype.net/blog/lifetype-development-journal/releases" xml:lang="en">http://www.lifetype.net/blog/lifetype-development-journal/releases</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22572" xml:lang="en">22572</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0616" xml:lang="en">ADV-2007-0616</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in LifeType before 1.1.6, and 1.2 before 1.2-beta2, allows remote attackers to obtain sensitive information (file contents) via a "crafted URL."</vuln:summary>
  </entry>
  <entry id="CVE-2007-0980">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:sg_a.11.16.9"/>
          <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:8_sg_a.11.15.6::enterprise_server"/>
          <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:9_sg_a.11.16.9::enterprise_server"/>
          <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:10_sg_a.11.16.9::enterprise_server"/>
          <cpe-lang:fact-ref name="cpe:/o:suse:suse_united_linux:1.0_sg_a.11.16.9"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:hp:serviceguard_for_linux:a.11.14.06"/>
          <cpe-lang:fact-ref name="cpe:/a:hp:serviceguard_for_linux:a.11.15.07"/>
          <cpe-lang:fact-ref name="cpe:/a:hp:serviceguard_for_linux:a.11.16.10"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hp:serviceguard_for_linux:a.11.14.06</vuln:product>
      <vuln:product>cpe:/a:hp:serviceguard_for_linux:a.11.15.07</vuln:product>
      <vuln:product>cpe:/a:hp:serviceguard_for_linux:a.11.16.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0980</vuln:cve-id>
    <vuln:published-datetime>2007-02-15T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:51:04.720-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00860750" xml:lang="en">SSRT071297</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22574" xml:lang="en">22574</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017655" xml:lang="en">1017655</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0619" xml:lang="en">ADV-2007-0619</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in HP Serviceguard for Linux; packaged for SuSE SLES8 and United Linux 1.0 before SG A.11.15.07, SuSE SLES9 and SLES10 before SG A.11.16.10, and Red Hat Enterprise Linux (RHEL) before SG A.11.16.10; allows remote attackers to obtain unauthorized access via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0981">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9:rc"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.6::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0:beta_1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:preview_release"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:firefox:0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9:rc</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.10.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.6::linux</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0:beta_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0:rc3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:preview_release</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0981</vuln:cve-id>
    <vuln:published-datetime>2007-02-15T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:50.047-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9730" name="oval:org.mitre.oval:def:9730"/>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc" xml:lang="en">20070202-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" xml:lang="en">20070301-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2713" xml:lang="en">FEDORA-2007-281</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2728" xml:lang="en">FEDORA-2007-293</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" xml:lang="en">HPSBUX02153</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://lcamtuf.dione.cc/ffhostname.html" xml:lang="en">http://lcamtuf.dione.cc/ffhostname.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html" xml:lang="en">SUSE-SA:2007:019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2007-0077.html" xml:lang="en">RHSA-2007:0077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200703-04.xml" xml:lang="en">GLSA-200703-04</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2262" xml:lang="en">2262</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017654" xml:lang="en">1017654</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131" xml:lang="en">SSA:2007-066-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.374851" xml:lang="en">SSA:2007-066-03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1336" xml:lang="en">DSA-1336</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml" xml:lang="en">GLSA-200703-08</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/885753" xml:lang="en">VU#885753</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:050" xml:lang="en">MDKSA-2007:050</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2007/mfsa2007-07.html" xml:lang="en">http://www.mozilla.org/security/announce/2007/mfsa2007-07.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html" xml:lang="en">SUSE-SA:2007:022</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0078.html" xml:lang="en">RHSA-2007:0078</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0079.html" xml:lang="en">RHSA-2007:0079</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0097.html" xml:lang="en">RHSA-2007:0097</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0108.html" xml:lang="en">RHSA-2007:0108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460126/100/200/threaded" xml:lang="en">20070214 Firefox: serious cookie stealing / same-domain bypass vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460217/100/0/threaded" xml:lang="en">20070215 Re: [Full-disclosure] Firefox: serious cookie stealing / same-domain bypass vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461336/100/0/threaded" xml:lang="en">20070226 rPSA-2007-0040-1 firefox</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461809/100/0/threaded" xml:lang="en">20070303 rPSA-2007-0040-3 firefox thunderbird</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22566" xml:lang="en">22566</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-428-1" xml:lang="en">USN-428-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0624" xml:lang="en">ADV-2007-0624</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0718" xml:lang="en">ADV-2007-0718</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0083" xml:lang="en">ADV-2008-0083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=370445" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=370445</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32533" xml:lang="en">firefox-locationhostname-security-bypass(32533)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1081" xml:lang="en">https://issues.rpath.com/browse/RPL-1081</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1103" xml:lang="en">https://issues.rpath.com/browse/RPL-1103</vuln:reference>
    </vuln:references>
    <vuln:summary>Mozilla based browsers, including Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8, allow remote attackers to bypass the same origin policy, steal cookies, and conduct other attacks by writing a URI with a null byte to the hostname (location.hostname) DOM property, due to interactions with DNS resolver code.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0982">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:taskfreak:taskfreak:0.5.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:taskfreak:taskfreak:0.5.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0982</vuln:cve-id>
    <vuln:published-datetime>2007-02-16T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2013-07-12T01:19:12.193-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22537" xml:lang="en">22537</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.taskfreak.com/versions.html" xml:lang="en">http://www.taskfreak.com/versions.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in error.php in TaskFreak! 0.5.5 allows remote attackers to inject arbitrary web script or HTML via the tznMessage parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0983">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ansatheus:at_contenator:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ansatheus:at_contenator:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0983</vuln:cve-id>
    <vuln:published-datetime>2007-02-16T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:06.583-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://attrition.org/pipermail/vim/2007-February/001312.html" xml:lang="en">20070213 true: AT Contenator &lt;= v1.0 (Root_To_Script) Remote File Include Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0606" xml:lang="en">ADV-2007-0606</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32453" xml:lang="en">atcontenator-nav-file-include(32453)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3297" xml:lang="en">3297</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in _admin/nav.php in AT Contenator 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the Root_To_Script parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0984">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:aspcode.net:pollmentor:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:aspcode.net:pollmentor:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0984</vuln:cve-id>
    <vuln:published-datetime>2007-02-16T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:42.360-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22542" xml:lang="en">22542</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0601" xml:lang="en">ADV-2007-0601</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32456" xml:lang="en">pollmentor-pollmentorres-sql-injection(32456)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3301" xml:lang="en">3301</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in admin_poll.asp in PollMentor 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to pollmentorres.asp.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0985">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpcc:phpcc:beta_4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpcc:phpcc:beta_4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0985</vuln:cve-id>
    <vuln:published-datetime>2007-02-16T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:42.423-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22540" xml:lang="en">22540</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0602" xml:lang="en">ADV-2007-0602</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3299" xml:lang="en">3299</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in nickpage.php in phpCC 4.2 beta and earlier allows remote attackers to execute arbitrary SQL commands via the npid parameter in a sign_gb action.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0986">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:jupiter_cms:jupiter_cms:1.1.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:jupiter_cms:jupiter_cms:1.1.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0986</vuln:cve-id>
    <vuln:published-datetime>2007-02-16T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:56.780-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://mgsdl.free.fr/advisories/12070214.txt" xml:lang="en">http://mgsdl.free.fr/advisories/12070214.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.acid-root.new.fr/advisories/12070214.txt" xml:lang="en">http://www.acid-root.new.fr/advisories/12070214.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460076/100/0/threaded" xml:lang="en">20070214 Jupiter CMS 1.1.5 Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460100/100/0/threaded" xml:lang="en">20070214 Re: Jupiter CMS 1.1.5 Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22560" xml:lang="en">22560</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32519" xml:lang="en">jupitercm-index-n-file-include(32519)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3309" xml:lang="en">3309</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in index.php in Jupiter CMS 1.1.5, when PHP 5.0.0 or later is used, allows remote attackers to execute arbitrary PHP code via an ftp URL in the n parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0987">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:jupiter_cms:jupiter_cms:1.1.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:jupiter_cms:jupiter_cms:1.1.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0987</vuln:cve-id>
    <vuln:published-datetime>2007-02-16T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:35:57.313-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://mgsdl.free.fr/advisories/12070214.txt" xml:lang="en">http://mgsdl.free.fr/advisories/12070214.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.acid-root.new.fr/advisories/12070214.txt" xml:lang="en">http://www.acid-root.new.fr/advisories/12070214.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460076/100/0/threaded" xml:lang="en">20070214 Jupiter CMS 1.1.5 Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460100/100/0/threaded" xml:lang="en">20070214 Re: Jupiter CMS 1.1.5 Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22560" xml:lang="en">22560</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3309" xml:lang="en">3309</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in index.php in Jupiter CMS 1.1.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot), or an absolute pathname, in the n parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0988">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0:beta_4_patch1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.1:rc"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.1:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.2:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.3:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.3:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.4:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.4:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.4:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.4:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.4:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.4:rc6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.5:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.5:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.5:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.5:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.5:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.5:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.5:rc6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.5:rc7"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.5:rc8"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.6:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.6:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.6:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.6:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.6:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.0:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.0:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.0:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.0:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.0:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.1:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.1:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.3:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.3:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.0:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.0:alpha1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.0:alpha2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.0:alpha3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.0:dev"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.0:pre1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.0:pre2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.0:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.2:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.2:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.2:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.2:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.3:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.3:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.3:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.3:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.4:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.4:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.4:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.5:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.5:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.5:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.5:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.5:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.6:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.6:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.6:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.6:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.7:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.7:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.9:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.9:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.9:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.10:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.10:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.10:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.11:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.11:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.11:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.0:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.1:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.2:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.2:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.3:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.3:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.4:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.1:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.1:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.1:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.1:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.2:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.3:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.3:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.3:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.4:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.4:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.4:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.5:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.5:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.5:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.0:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.0:rc2-pre"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.0:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.0:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.0:rc6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.2:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.2:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.2:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.3:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.3:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.3:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.5:-"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.5:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.0:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.0:rc5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.0:rc6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:5.10"/>
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:6.06::~~lts~~~"/>
        <cpe-lang:fact-ref name="cpe:/o:canonical:ubuntu_linux:6.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:php:4.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0:beta1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0:beta2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0:beta3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0:beta4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0:beta_4_patch1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.1:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.1:rc</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.1:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.2:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.3:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.3:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.4:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.4:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.4:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.4:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.4:rc4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.4:rc5</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.4:rc6</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.5</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.5:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.5:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.5:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.5:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.5:rc4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.5:rc5</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.5:rc6</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.5:rc7</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.5:rc8</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.6</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.6:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.6:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.6:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.6:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.6:rc4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.0:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.0:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.0:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.0:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.0:rc4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.0:rc5</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.0:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.0:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.0:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.0:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.0:rc4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.1:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.1:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.1:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.3:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.3:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.3:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.0:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.0:alpha1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.0:alpha2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.0:alpha3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.0:dev</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.0:pre1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.0:pre2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.0:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.0:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.0:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.0:rc4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.2:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.2:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.2:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.2:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.2:rc4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.3:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.3:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.3:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.3:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.3:rc4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.4:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.4:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.4:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.4:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.5</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.5:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.5:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.5:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.5:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.5:rc4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.6</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.6:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.6:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.6:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.6:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.7</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.7:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.7:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.8</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.9</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.9:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.9:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.9:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.10</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.10:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.10:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.10:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.11</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.11:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.11:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.11:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.0:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.0:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.0:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.1:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.1:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.2:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.2:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.2:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.3:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.3:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.3:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.4:-</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.4:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:-</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:beta1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:beta2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:beta3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:beta4</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.1:-</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.1:beta1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.1:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.1:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.2:-</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.2:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.3:-</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.3:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.3:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.4</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.4:-</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.4:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.4:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.5</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.5:-</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.5:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.5:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.0</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.0:-</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.0:beta1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.0:beta2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.0:beta3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.0:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.0:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.0:rc2-pre</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.0:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.0:rc4</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.0:rc5</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.0:rc6</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.2:-</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.2:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.2:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.3:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.3:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.3:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.4</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.5</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.5:-</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.5:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.6</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.0</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.0:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.0:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.0:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.0:rc4</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.0:rc5</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.0:rc6</vuln:product>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:5.10</vuln:product>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:6.06::~~lts~~~</vuln:product>
      <vuln:product>cpe:/o:canonical:ubuntu_linux:6.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0988</vuln:cve-id>
    <vuln:published-datetime>2007-02-20T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-10-09T18:52:17.180-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11092" name="oval:org.mitre.oval:def:11092"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc" xml:lang="en">20070201-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=228858" xml:lang="en">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=228858</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01056506" xml:lang="en">SSRT071423</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01086137" xml:lang="en">HPSBTU02232</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2007-0089.html" xml:lang="en">RHSA-2007:0089</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200703-21.xml" xml:lang="en">GLSA-200703-21</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2315" xml:lang="en">2315</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2007-101.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2007-101.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2007-136.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2007-136.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:048" xml:lang="en">MDKSA-2007:048</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_32_php.html" xml:lang="en">SUSE-SA:2007:032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>OPENPKG</vuln:source>
      <vuln:reference href="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.010.html" xml:lang="en">OpenPKG-SA-2007.010</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.php.net/releases/5_2_1.php" xml:lang="en">http://www.php.net/releases/5_2_1.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.php-security.org/MOPB/MOPB-05-2007.html" xml:lang="en">http://www.php-security.org/MOPB/MOPB-05-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0076.html" xml:lang="en">RHSA-2007:0076</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0081.html" xml:lang="en">RHSA-2007:0081</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0082.html" xml:lang="en">RHSA-2007:0082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0088.html" xml:lang="en">RHSA-2007:0088</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461462/100/0/threaded" xml:lang="en">20070227 rPSA-2007-0043-1 php php-mysql php-pgsql</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017671" xml:lang="en">1017671</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2007/0009/" xml:lang="en">2007-0009</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-424-1" xml:lang="en">USN-424-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-424-2" xml:lang="en">USN-424-2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.us.debian.org/security/2007/dsa-1264" xml:lang="en">DSA-1264</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1991" xml:lang="en">ADV-2007-1991</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2374" xml:lang="en">ADV-2007-2374</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32709" xml:lang="en">php-zendhashinit-dos(32709)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1088" xml:lang="en">https://issues.rpath.com/browse/RPL-1088</vuln:reference>
    </vuln:references>
    <vuln:summary>The zend_hash_init function in PHP 5 before 5.2.1 and PHP 4 before 4.4.5, when running on a 64-bit platform, allows context-dependent attackers to cause a denial of service (infinite loop) by unserializing certain integer expressions, which only cause 32-bit arguments to be used after the check for a negative value, as demonstrated by an "a:2147483649:{" argument.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0989">
    <vuln:cve-id>CVE-2007-0989</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:05.683-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:05.683-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2007. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0990">
    <vuln:cve-id>CVE-2007-0990</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:05.713-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:05.713-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2007. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0991">
    <vuln:cve-id>CVE-2007-0991</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:05.730-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:05.747-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2007. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0992">
    <vuln:cve-id>CVE-2007-0992</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:05.760-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:05.760-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2007. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0993">
    <vuln:cve-id>CVE-2007-0993</vuln:cve-id>
    <vuln:published-datetime>2007-06-05T17:30:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:50:22.070-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2007-0933.  Reason: This candidate is a duplicate of CVE-2007-0933 due to a typo.  Notes: All CVE users should reference CVE-2007-0933 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0994">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1::alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1::beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1:beta"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:firefox:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1::alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1::beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1:beta</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0994</vuln:cve-id>
    <vuln:published-datetime>2007-03-05T19:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-10-09T18:52:17.553-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9749" name="oval:org.mitre.oval:def:9749"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc" xml:lang="en">20070202-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" xml:lang="en">20070301-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=230733" xml:lang="en">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=230733</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" xml:lang="en">SSRT061181</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html" xml:lang="en">SUSE-SA:2007:019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017726" xml:lang="en">1017726</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131" xml:lang="en">SSA:2007-066-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.374851" xml:lang="en">SSA:2007-066-03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1336" xml:lang="en">DSA-1336</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2007/mfsa2007-09.html" xml:lang="en">http://www.mozilla.org/security/announce/2007/mfsa2007-09.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html" xml:lang="en">SUSE-SA:2007:022</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0097.html" xml:lang="en">RHSA-2007:0097</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22826" xml:lang="en">22826</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0823" xml:lang="en">ADV-2007-0823</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1103" xml:lang="en">https://issues.rpath.com/browse/RPL-1103</vuln:reference>
    </vuln:references>
    <vuln:summary>A regression error in Mozilla Firefox 2.x before 2.0.0.2 and 1.x before 1.5.0.10, and SeaMonkey 1.1 before 1.1.1 and 1.0 before 1.0.8, allows remote attackers to execute arbitrary JavaScript as the user via an HTML mail message with a javascript: URI in an (1) img, (2) link, or (3) style tag, which bypasses the access checks and executes code with chrome privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0995">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0995</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T14:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:02.547-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10164" name="oval:org.mitre.oval:def:10164"/>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc" xml:lang="en">20070202-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" xml:lang="en">20070301-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2713" xml:lang="en">FEDORA-2007-281</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2728" xml:lang="en">FEDORA-2007-293</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" xml:lang="en">HPSBUX02153</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://ha.ckers.org/xss.html#XSS_Non_alpha_non_digit2" xml:lang="en">http://ha.ckers.org/xss.html#XSS_Non_alpha_non_digit2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html" xml:lang="en">SUSE-SA:2007:019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2007-0077.html" xml:lang="en">RHSA-2007:0077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200703-04.xml" xml:lang="en">GLSA-200703-04</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131" xml:lang="en">SSA:2007-066-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.374851" xml:lang="en">SSA:2007-066-03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1336" xml:lang="en">DSA-1336</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml" xml:lang="en">GLSA-200703-08</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:050" xml:lang="en">MDKSA-2007:050</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2007/mfsa2007-02.html" xml:lang="en">http://www.mozilla.org/security/announce/2007/mfsa2007-02.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html" xml:lang="en">SUSE-SA:2007:022</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0078.html" xml:lang="en">RHSA-2007:0078</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0079.html" xml:lang="en">RHSA-2007:0079</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0097.html" xml:lang="en">RHSA-2007:0097</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0108.html" xml:lang="en">RHSA-2007:0108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461336/100/0/threaded" xml:lang="en">20070226 rPSA-2007-0040-1 firefox</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461809/100/0/threaded" xml:lang="en">20070303 rPSA-2007-0040-3 firefox thunderbird</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22694" xml:lang="en">22694</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017702" xml:lang="en">1017702</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-428-1" xml:lang="en">USN-428-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0718" xml:lang="en">ADV-2007-0718</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0083" xml:lang="en">ADV-2008-0083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1081" xml:lang="en">https://issues.rpath.com/browse/RPL-1081</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1103" xml:lang="en">https://issues.rpath.com/browse/RPL-1103</vuln:reference>
    </vuln:references>
    <vuln:summary>Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 ignores trailing invalid HTML characters in attribute names, which allows remote attackers to bypass content filters that use regular expressions.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0996">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0:beta_1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0::alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0::dev"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:firefox:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0:beta_1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0:rc2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0:rc3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0::alpha</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0::dev</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0:beta</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0996</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:07.157-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10086" name="oval:org.mitre.oval:def:10086"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc" xml:lang="en">20070202-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" xml:lang="en">20070301-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2713" xml:lang="en">FEDORA-2007-281</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2728" xml:lang="en">FEDORA-2007-293</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" xml:lang="en">HPSBUX02153</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html" xml:lang="en">SUSE-SA:2007:019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2007-0077.html" xml:lang="en">RHSA-2007:0077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131" xml:lang="en">SSA:2007-066-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.374851" xml:lang="en">SSA:2007-066-03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1336" xml:lang="en">DSA-1336</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.hardened-php.net/advisory_032007.142.html" xml:lang="en">http://www.hardened-php.net/advisory_032007.142.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:050" xml:lang="en">MDKSA-2007:050</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2007/mfsa2007-02.html" xml:lang="en">http://www.mozilla.org/security/announce/2007/mfsa2007-02.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html" xml:lang="en">SUSE-SA:2007:022</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0078.html" xml:lang="en">RHSA-2007:0078</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0079.html" xml:lang="en">RHSA-2007:0079</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0097.html" xml:lang="en">RHSA-2007:0097</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0108.html" xml:lang="en">RHSA-2007:0108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461076/100/0/threaded" xml:lang="en">20070223 Advisory 03/2007: Multiple Browsers Cross Domain Charset Inheritance Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461336/100/0/threaded" xml:lang="en">20070226 rPSA-2007-0040-1 firefox</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22694" xml:lang="en">22694</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017702" xml:lang="en">1017702</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-428-1" xml:lang="en">USN-428-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0718" xml:lang="en">ADV-2007-0718</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1103" xml:lang="en">https://issues.rpath.com/browse/RPL-1103</vuln:reference>
    </vuln:references>
    <vuln:summary>The child frames in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 inherit the default charset from the parent window, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated using the UTF-7 character set.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0997">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0997</vuln:cve-id>
    <vuln:published-datetime>2007-09-18T15:17:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:19:22.830-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-09-19T15:45:00.000-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-362"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.18" xml:lang="en">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lkml.org/lkml/2006/7/17/140" xml:lang="en">[linux-kernel] 20060717 [patch 25/45] splice: fix problems with sys_tee()</vuln:reference>
    </vuln:references>
    <vuln:summary>Race condition in the tee (sys_tee) system call in the Linux kernel 2.6.17 through 2.6.17.6 might allow local users to cause a denial of service (system crash), obtain sensitive information (kernel memory contents), or gain privileges via unspecified vectors related to a potentially dropped ipipe lock during a race between two pipe readers.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0998">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:5.0::desktop"/>
          <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:5.0::desktop_multiple_os"/>
          <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:5.0::server"/>
          <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:5.0::virtualization"/>
          <cpe-lang:fact-ref name="cpe:/o:redhat:fedora_core:core6"/>
          <cpe-lang:fact-ref name="cpe:/o:redhat:fedora_core:core_5.0"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:xen:qemu"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xen:qemu</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0998</vuln:cve-id>
    <vuln:published-datetime>2007-03-20T06:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:42.860-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10486" name="oval:org.mitre.oval:def:10486"/>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00017.html" xml:lang="en">openSUSE-SU-2012:1572</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00018.html" xml:lang="en">openSUSE-SU-2012:1573</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.html" xml:lang="en">SUSE-SU-2014:0446</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2007-0114.html" xml:lang="en">RHSA-2007:0114</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22967" xml:lang="en">22967</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017764" xml:lang="en">1017764</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1019" xml:lang="en">ADV-2007-1019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1020" xml:lang="en">ADV-2007-1020</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1021" xml:lang="en">ADV-2007-1021</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33085" xml:lang="en">fedora-xen-qemuvnc-information-disclosure(33085)</vuln:reference>
    </vuln:references>
    <vuln:summary>The VNC server implementation in QEMU, as used by Xen and possibly other environments, allows local users of a guest operating system to read arbitrary files on the host operating system via unspecified vectors related to QEMU monitor mode, as demonstrated by mapping files to a CDROM device.  NOTE: some of these details are obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-0999">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gnome:ekiga:2.0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnome:ekiga:2.0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-0999</vuln:cve-id>
    <vuln:published-datetime>2007-03-10T14:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:42.923-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10944" name="oval:org.mitre.oval:def:10944"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:058" xml:lang="en">MDKSA-2007:058</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0087.html" xml:lang="en">RHSA-2007:0087</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-434-1" xml:lang="en">USN-434-1</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in Ekiga 2.0.3, and probably other versions, allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2007-1006.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1000">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1000</vuln:cve-id>
    <vuln:published-datetime>2007-03-12T19:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:42.987-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10015" name="oval:org.mitre.oval:def:10015"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugzilla.kernel.org/show_bug.cgi?id=8134" xml:lang="en">http://bugzilla.kernel.org/show_bug.cgi?id=8134</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2787" xml:lang="en">FEDORA-2007-335</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2788" xml:lang="en">FEDORA-2007-336</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-May/0001.html" xml:lang="en">SUSE-SA:2007:029</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/920689" xml:lang="en">VU#920689</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20.2" xml:lang="en">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20.2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:078" xml:lang="en">MDKSA-2007:078</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0169.html" xml:lang="en">RHSA-2007:0169</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/471457" xml:lang="en">20070615 rPSA-2007-0124-1 kernel xen</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22904" xml:lang="en">22904</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-486-1" xml:lang="en">USN-486-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-489-1" xml:lang="en">USN-489-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0907" xml:lang="en">ADV-2007-0907</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.wslabi.com/wabisabilabi/initPublishedBid.do?" xml:lang="en">http://www.wslabi.com/wabisabilabi/initPublishedBid.do?</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1153" xml:lang="en">https://issues.rpath.com/browse/RPL-1153</vuln:reference>
    </vuln:references>
    <vuln:summary>The ipv6_getsockopt_sticky function in net/ipv6/ipv6_sockglue.c in the Linux kernel before 2.6.20.2 allows local users to read arbitrary kernel memory via certain getsockopt calls that trigger a NULL dereference.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1001">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0:beta_4_patch1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.1:patch1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.1:patch2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.3:patch1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.4:patch1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2::dev"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:beta3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:beta4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.0:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:php:4.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0:beta1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0:beta2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0:beta3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0:beta4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0:beta_4_patch1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.1:patch1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.1:patch2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.3:patch1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.4:patch1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.5</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.6</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2::dev</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.5</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.6</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.7</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.8</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.9</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.10</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.11</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.5</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.6</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:beta1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:beta2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:beta3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:beta4</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.0:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.4</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.5</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.0</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.4</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.5</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.6</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.0</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1001</vuln:cve-id>
    <vuln:published-datetime>2007-04-05T20:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:35.747-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10179" name="oval:org.mitre.oval:def:10179"/>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://cvs.php.net/viewvc.cgi/php-src/ext/gd/libgd/wbmp.c?r1=1.2.4.1&amp;r2=1.2.4.1.8.1" xml:lang="en">http://cvs.php.net/viewvc.cgi/php-src/ext/gd/libgd/wbmp.c?r1=1.2.4.1&amp;r2=1.2.4.1.8.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://cvs.php.net/viewvc.cgi/php-src/ext/gd/libgd/wbmp.c?revision=1.2.4.1.8.1&amp;view=markup" xml:lang="en">http://cvs.php.net/viewvc.cgi/php-src/ext/gd/libgd/wbmp.c?revision=1.2.4.1.8.1&amp;view=markup</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=306172" xml:lang="en">http://docs.info.apple.com/article.html?artnum=306172</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://ifsec.blogspot.com/2007/04/php-521-wbmp-file-handling-integer.html" xml:lang="en">http://ifsec.blogspot.com/2007/04/php-521-wbmp-file-handling-integer.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html" xml:lang="en">APPLE-SA-2007-07-31</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2007-0155.html" xml:lang="en">RHSA-2007:0155</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200705-19.xml" xml:lang="en">GLSA-200705-19</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://us2.php.net/releases/4_4_7.php" xml:lang="en">http://us2.php.net/releases/4_4_7.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://us2.php.net/releases/5_2_2.php" xml:lang="en">http://us2.php.net/releases/5_2_2.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:087" xml:lang="en">MDKSA-2007:087</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:088" xml:lang="en">MDKSA-2007:088</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:089" xml:lang="en">MDKSA-2007:089</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:090" xml:lang="en">MDKSA-2007:090</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_32_php.html" xml:lang="en">SUSE-SA:2007:032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0153.html" xml:lang="en">RHSA-2007:0153</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0162.html" xml:lang="en">RHSA-2007:0162</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/464957/100/0/threaded" xml:lang="en">20070407 PHP &lt;= 5.2.1 wbmp file handling integer overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/466166/100/0/threaded" xml:lang="en">20070418 rPSA-2007-0073-1 php php-mysql php-pgsql</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23357" xml:lang="en">23357</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/25159" xml:lang="en">25159</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://www.slackware.org/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.470053" xml:lang="en">SSA:2007-127</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1269" xml:lang="en">ADV-2007-1269</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2732" xml:lang="en">ADV-2007-2732</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33453" xml:lang="en">php-gd-overflow(33453)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1268" xml:lang="en">https://issues.rpath.com/browse/RPL-1268</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple integer overflows in the (1) createwbmp and (2) readwbmp functions in wbmp.c in the GD library (libgd) in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allow context-dependent attackers to execute arbitrary code via Wireless Bitmap (WBMP) images with large width or height values.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1002">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:evolution:shared_memo:2.8.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:evolution:shared_memo:2.8.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1002</vuln:cve-id>
    <vuln:published-datetime>2007-03-21T18:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:15.093-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10100" name="oval:org.mitre.oval:def:10100"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200706-02.xml" xml:lang="en">GLSA-200706-02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1325" xml:lang="en">DSA-1325</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:070" xml:lang="en">MDKSA-2007:070</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_15_sr.html" xml:lang="en">SUSE-SR:2007:015</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/463406/100/0/threaded" xml:lang="en">20070321 Secunia Research: Evolution Shared Memo Categories Format StringVulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/464820/30/7170/threaded" xml:lang="en">20070405 FLEA-2007-0010-1: evolution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23073" xml:lang="en">23073</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017808" xml:lang="en">1017808</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-442-1" xml:lang="en">USN-442-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1058" xml:lang="en">ADV-2007-1058</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33106" xml:lang="en">evolution-writehtml-format-string(33106)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="https://rhn.redhat.com/errata/RHSA-2007-0158.html" xml:lang="en">RHSA-2007:0158</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in the write_html function in calendar/gui/e-cal-component-memo-preview.c in Evolution Shared Memo 2.8.2.1, and possibly earlier versions, allows user-assisted remote attackers to execute arbitrary code via format specifiers in the categories of a crafted shared memo.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1003">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:x.org:x11:7.1_1.1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:x.org:x11:7.1_1.1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1003</vuln:cve-id>
    <vuln:published-datetime>2007-04-05T21:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:16.687-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1980" name="oval:org.mitre.oval:def:1980"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9798" name="oval:org.mitre.oval:def:9798"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://issues.foresightlinux.org/browse/FL-223" xml:lang="en">http://issues.foresightlinux.org/browse/FL-223</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=503" xml:lang="en">20070403 Multiple Vendor X Server XC-MISC Extension Memory Corruption Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.freedesktop.org/archives/xorg-announce/2007-April/000286.html" xml:lang="en">[xorg-announce] 20070403 various integer overflow vulnerabilites in xserver, libX11 and libXfont</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00005.html" xml:lang="en">SUSE-SR:2008:008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2007-0125.html" xml:lang="en">RHSA-2007:0125</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200705-10.xml" xml:lang="en">GLSA-200705-10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102886-1" xml:lang="en">102886</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2007-178.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2007-178.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1294" xml:lang="en">DSA-1294</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:079" xml:lang="en">MDKSA-2007:079</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:080" xml:lang="en">MDKSA-2007:080</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_27_x.html" xml:lang="en">SUSE-SA:2007:027</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OPENBSD</vuln:source>
      <vuln:reference href="http://www.openbsd.org/errata39.html#021_xorg" xml:lang="en">[3.9] 021: SECURITY FIX: April 4, 2007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OPENBSD</vuln:source>
      <vuln:reference href="http://www.openbsd.org/errata40.html#011_xorg" xml:lang="en">[4.0] 011: SECURITY FIX: April 4, 2007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0126.html" xml:lang="en">RHSA-2007:0126</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0127.html" xml:lang="en">RHSA-2007:0127</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/464686/100/0/threaded" xml:lang="en">20070404 rPSA-2007-0065-1 freetype xorg-x11 xorg-x11-fonts xorg-x11-tools xorg-x11-xfs</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/464816/100/0/threaded" xml:lang="en">20070405 FLEA-2007-0009-1: xorg-x11 freetype</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23284" xml:lang="en">23284</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23300" xml:lang="en">23300</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017857" xml:lang="en">1017857</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-448-1" xml:lang="en">USN-448-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1217" xml:lang="en">ADV-2007-1217</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1548" xml:lang="en">ADV-2007-1548</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33424" xml:lang="en">xorg-xcmisc-overflow(33424)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1213" xml:lang="en">https://issues.rpath.com/browse/RPL-1213</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in ALLOCATE_LOCAL in the ProcXCMiscGetXIDList function in the XC-MISC extension in the X.Org X11 server (xserver) 7.1-1.1.0, and other versions before 20070403, allows remote authenticated users to execute arbitrary code via a large expression, which results in memory corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1004">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0:rc3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:firefox:2.0:rc3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1004</vuln:cve-id>
    <vuln:published-datetime>2007-02-19T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:21.640-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2264" xml:lang="en">2264</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460369/100/0/threaded" xml:lang="en">20070216 Firefox: about:blank is phisher's best friend</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460412/100/0/threaded" xml:lang="en">20070217 Re: Firefox: about:blank is phisher's best friend</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460617/100/0/threaded" xml:lang="en">20070219 RE: Firefox: about:blank is phisher's best friend</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22601" xml:lang="en">22601</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32580" xml:lang="en">firefox-aboutblank-security-bypass(32580)</vuln:reference>
    </vuln:references>
    <vuln:summary>Mozilla Firefox might allow remote attackers to conduct spoofing and phishing attacks by writing to an about:blank tab and overlaying the location bar.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1005">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ca:etrust_intrusion_detection:2.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:etrust_intrusion_detection:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:etrust_intrusion_detection:3.0:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ca:etrust_intrusion_detection:2.0:sp1</vuln:product>
      <vuln:product>cpe:/a:ca:etrust_intrusion_detection:3.0</vuln:product>
      <vuln:product>cpe:/a:ca:etrust_intrusion_detection:3.0:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1005</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:22.377-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=484" xml:lang="en">20070227 Computer Associates eTrust Intrusion Detection Denial of Service Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://supportconnectw.ca.com/public/ca_common_docs/eid_secnotice.asp" xml:lang="en">http://supportconnectw.ca.com/public/ca_common_docs/eid_secnotice.asp</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461567/100/100/threaded" xml:lang="en">20070228 [CAID 35112]: CA eTrust Intrusion Detection Denial of Service Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22743" xml:lang="en">22743</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017706" xml:lang="en">1017706</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0776" xml:lang="en">ADV-2007-0776</vuln:reference>
    </vuln:references>
    <vuln:summary>Heap-based buffer overflow in SW3eng.exe in the eID Engine service in CA (formerly Computer Associates) eTrust Intrusion Detection 3.0.5.57 and earlier allows remote attackers to cause a denial of service (application crash) via a long key length value to the remote administration port (9191/tcp).</vuln:summary>
  </entry>
  <entry id="CVE-2007-1006">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ekiga:ekiga:2.0.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ekiga:ekiga:2.0.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1006</vuln:cve-id>
    <vuln:published-datetime>2007-02-19T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:43.347-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11642" name="oval:org.mitre.oval:def:11642"/>
    <vuln:cwe id="CWE-134"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2682" xml:lang="en">FEDORA-2007-262</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2683" xml:lang="en">FEDORA-2007-263</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://labs.musecurity.com/advisories/MU-200702-01.txt" xml:lang="en">http://labs.musecurity.com/advisories/MU-200702-01.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://mail.gnome.org/archives/ekiga-list/2007-February/msg00060.html" xml:lang="en">[Ekiga-list] 20070213 Ekiga 2.0.5 available</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200703-25.xml" xml:lang="en">GLSA-200703-25</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1262" xml:lang="en">DSA-1262</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.ekiga.org/index.php?rub=10&amp;archive=1" xml:lang="en">http://www.ekiga.org/index.php?rub=10&amp;archive=1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:044" xml:lang="en">MDKSA-2007:044</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_9_sr.html" xml:lang="en">SUSE-SR:2007:009</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0087.html" xml:lang="en">RHSA-2007:0087</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22613" xml:lang="en">22613</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017673" xml:lang="en">1017673</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-426-1" xml:lang="en">USN-426-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0655" xml:lang="en">ADV-2007-0655</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple format string vulnerabilities in the gm_main_window_flash_message function in Ekiga before 2.0.5 allow attackers to cause a denial of service and possibly execute arbitrary code via a crafted Q.931 SETUP packet.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1007">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ekiga:ekiga:1.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::advanced_servers"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_desktop:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_desktop:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ekiga:ekiga:1.0.2</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::advanced_servers</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::workstation</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::advanced_server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::workstation</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux_desktop:3.0</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux_desktop:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1007</vuln:cve-id>
    <vuln:published-datetime>2007-02-20T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:43.423-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11776" name="oval:org.mitre.oval:def:11776"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc" xml:lang="en">20070201-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=229266" xml:lang="en">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=229266</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1262" xml:lang="en">DSA-1262</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:045" xml:lang="en">MDKSA-2007:045</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_9_sr.html" xml:lang="en">SUSE-SR:2007:009</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0086.html" xml:lang="en">RHSA-2007:0086</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-426-1" xml:lang="en">USN-426-1</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in GnomeMeeting 1.0.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in the name, which is not properly handled in a call to the gnomemeeting_log_insert function.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1008">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apple:itunes:7.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:itunes:7.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1008</vuln:cve-id>
    <vuln:published-datetime>2007-02-19T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:22.890-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16978" name="oval:org.mitre.oval:def:16978"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2278" xml:lang="en">2278</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460544/100/0/threaded" xml:lang="en">20070219 iTunes remote memory corruption vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22615" xml:lang="en">22615</vuln:reference>
    </vuln:references>
    <vuln:summary>Apple iTunes 7.0.2 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted XML list of radio stations, which results in memory corruption.  NOTE: iTunes retrieves the XML document from a static URL, which requires an attacker to perform DNS spoofing or man-in-the-middle attacks for exploitation.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1009">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:macrovision:installanywhere:8::enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:macrovision:installanywhere:8::standard"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:macrovision:installanywhere:8::enterprise</vuln:product>
      <vuln:product>cpe:/a:macrovision:installanywhere:8::standard</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1009</vuln:cve-id>
    <vuln:published-datetime>2007-04-19T06:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:23.377-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2596" xml:lang="en">2596</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/466035/100/0/threaded" xml:lang="en">20070416 SYMSA-2007-003 Macrovision InstallAnywhere Password and Serial Number Bypass</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22643" xml:lang="en">22643</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.symantec.com/content/en/us/enterprise/research/SYMSA-2007-003.txt" xml:lang="en">http://www.symantec.com/content/en/us/enterprise/research/SYMSA-2007-003.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1433" xml:lang="en">ADV-2007-1433</vuln:reference>
    </vuln:references>
    <vuln:summary>Macrovision InstallAnywhere Enterprise before 8.0.1 uses the InstallScript.iap_xml configuration file without integrity protection to verify authorization for installing an application, which allows local users to perform unauthorized installations by removing the (1) password or (2) serial number verification sections from this file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1010">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:zebrafeeds:zebrafeeds:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:zebrafeeds:zebrafeeds:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1010</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:43.533-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://cazalet.org/category/zebrafeeds" xml:lang="en">http://cazalet.org/category/zebrafeeds</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://cazalet.org/zebrafeeds/forums/viewtopic.php?pid=358" xml:lang="en">http://cazalet.org/zebrafeeds/forums/viewtopic.php?pid=358</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22576" xml:lang="en">22576</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0622" xml:lang="en">ADV-2007-0622</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32507" xml:lang="en">zebrafeeds-zfpath-file-include(32507)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3314" xml:lang="en">3314</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple PHP remote file inclusion vulnerabilities in ZebraFeeds 1.0, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the zf_path parameter to (1) aggregator.php and (2) controller.php in newsfeeds/includes/.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1011">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:vs-gastebuch:vs-gastebuch:1.5.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vs-gastebuch:vs-gastebuch:1.5.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1011</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:06.787-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22605" xml:lang="en">22605</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0646" xml:lang="en">ADV-2007-0646</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32555" xml:lang="en">vsgastebuch-functions-file-include(32555)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3328" xml:lang="en">3328</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in functions_inc.php in VS-Gastebuch 1.5.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the gb_pfad parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1012">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:deskpro:deskpro:1.1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:deskpro:deskpro:1.1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1012</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:23.657-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2267" xml:lang="en">2267</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460200/100/0/threaded" xml:lang="en">20070214 XSS in [deskpro.com v1.1.0 ]</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32525" xml:lang="en">deskprocom-faq-xss(32525)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in faq.php in DeskPRO 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the article parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1013">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:virtualsystem:htaccess_passwort_generator:1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:virtualsystem:htaccess_passwort_generator:1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1013</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:43.597-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22598" xml:lang="en">22598</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0643" xml:lang="en">ADV-2007-0643</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32559" xml:lang="en">htaccess-generate-file-include(32559)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3324" xml:lang="en">3324</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in generate.php in VirtualSystem Htaccess Passwort Generator 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the ht_pfad parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1014">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:vicftps:vicftps:3.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vicftps:vicftps:3.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1014</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:43.657-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://vicftps.50webs.com/" xml:lang="en">http://vicftps.50webs.com/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22608" xml:lang="en">22608</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0648" xml:lang="en">ADV-2007-0648</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32557" xml:lang="en">vicftps-cwd-bo(32557)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3331" xml:lang="en">3331</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in VicFTPS before 5.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long CWD command.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1015">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:aktueldownload:aktueldownload_haber_script"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:aktueldownload:aktueldownload_haber_script</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1015</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:43.707-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0620" xml:lang="en">ADV-2007-0620</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32527" xml:lang="en">aktueldownload-haberdetay-sql-injection(32527)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3318" xml:lang="en">3318</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in HaberDetay.asp in Aktueldownload Haber script allows remote attackers to execute arbitrary SQL commands via the id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1016">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:aktueldownload:aktueldownload_haber_script"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:aktueldownload:aktueldownload_haber_script</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1016</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:51:08.687-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0620" xml:lang="en">ADV-2007-0620</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in Aktueldownload Haber script allows remote attackers to execute arbitrary SQL commands via certain vectors related to the HaberDetay.asp and rss.asp components, and the id and kid parameters.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  NOTE: the combination of the HaberDetay.asp component and the id parameter is already covered by another February 2007 CVE candidate.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1017">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:virtualsystem:vs-news-system:1.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:virtualsystem:vs-news-system:1.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1017</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:43.753-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22592" xml:lang="en">22592</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0649" xml:lang="en">ADV-2007-0649</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32544" xml:lang="en">vsnewssystem-shownewsinc-file-include(32544)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3322" xml:lang="en">3322</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in show_news_inc.php in VirtualSystem VS-News-System 1.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the newsordner parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1018">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:virtualsystem:vs-news-system:1.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:virtualsystem:vs-news-system:1.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1018</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:42:52.203-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>PHP remote file inclusion vulnerability in tpl/header.php in VirtualSystem VS-News-System 1.2.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the newsordner parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1019">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:webspell:webspell:4.01.02"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:webspell:webspell:4.01.02</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1019</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:43.813-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22541" xml:lang="en">22541</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0650" xml:lang="en">ADV-2007-0650</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32554" xml:lang="en">webspell-showonly-sql-injection(32554)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3325" xml:lang="en">3325</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in news.php in webSPELL 4.01.02, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the showonly parameter to index.php, a different vector than CVE-2006-5388.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1020">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cedstat:cedstat:1.31"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cedstat:cedstat:1.31</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1020</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:23.967-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://forums.avenir-geopolitique.net/viewtopic.php?t=2672" xml:lang="en">http://forums.avenir-geopolitique.net/viewtopic.php?t=2672</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2265" xml:lang="en">2265</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460260/100/0/threaded" xml:lang="en">20070215 CedStat v1.31 XSS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22588" xml:lang="en">22588</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22653" xml:lang="en">22653</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0680" xml:lang="en">ADV-2007-0680</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32537" xml:lang="en">cedstat-index-xss(32537)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in index.php in CedStat 1.31 allows remote attackers to inject arbitrary web script or HTML via the hier parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1021">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:xfairguy:codeavalanche_news:1.x"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xfairguy:codeavalanche_news:1.x</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1021</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:43.970-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22582" xml:lang="en">22582</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0621" xml:lang="en">ADV-2007-0621</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32528" xml:lang="en">codeavalanche-inclistnews-sql-injection(32528)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3317" xml:lang="en">3317</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in inc_listnews.asp in CodeAvalanche News 1.x allows remote attackers to execute arbitrary SQL commands via the CAT_ID parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1022">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:turuncu_portal:turuncu_portal:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:turuncu_portal:turuncu_portal:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1022</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:34.250-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22591" xml:lang="en">22591</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32571" xml:lang="en">turuncu-hgoster-sql-injection(32571)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in h_goster.asp in Turuncu Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1023">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:snitz_communications:snitz_forums_2000:3.1:sr4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:snitz_communications:snitz_forums_2000:3.1:sr4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1023</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:44.063-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22593" xml:lang="en">22593</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32543" xml:lang="en">snitzforums-popprofile-sql-injection(32543)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3321" xml:lang="en">3321</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in pop_profile.asp in Snitz Forums 2000 3.1 SR4 allows remote attackers to execute arbitrary SQL commands via the id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1024">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:marcello_vitagliano:meganoides_news:1.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:marcello_vitagliano:meganoides_news:1.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1024</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:24.467-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://attrition.org/pipermail/vim/2007-February/001361.html" xml:lang="en">20070220 [True] Meganoide's news v1.1.1 &lt; = RFi Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2266" xml:lang="en">2266</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460323/100/0/threaded" xml:lang="en">20070216 Meganoide's news v1.1.1 &lt; = RFi Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22589" xml:lang="en">22589</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32546" xml:lang="en">meganoidesnews-include-file-include(32546)</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in include.php in Meganoide's news 1.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the _SERVER[DOCUMENT_ROOT] parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1025">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:virtualsystem:vs-link-partner:2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:virtualsystem:vs-link-partner:2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1025</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:44.283-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22594" xml:lang="en">22594</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0651" xml:lang="en">ADV-2007-0651</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32547" xml:lang="en">vslinkpartner-functions-file-include(32547)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3323" xml:lang="en">3323</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in inc/functions_inc.php in VS-Link-Partner 2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the gb_pfad, or possibly script_pfad, parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1026">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:scriptdungeon:xlatunes:0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:scriptdungeon:xlatunes:0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1026</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:24.860-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460592/100/0/threaded" xml:lang="en">20070219 XLAtunes 0.1 (album) Remote SQL Injection Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460621/100/0/threaded" xml:lang="en">20070220 Re: XLAtunes 0.1 (album) Remote SQL Injection Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460739/100/0/threaded" xml:lang="en">20070221 XLAtunes 0.1 (album) Remote SQL Injection Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22602" xml:lang="en">22602</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0644" xml:lang="en">ADV-2007-0644</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32556" xml:lang="en">xlatunes-album-sql-injection(32556)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3327" xml:lang="en">3327</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in view.php in XLAtunes 0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the album parameter in view mode.  NOTE: some of these details are obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1027">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:9.0::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:9.0::unix"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:db2:9.0::linux</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:9.0::unix</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1027</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:51:10.110-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.4</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-59"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22614" xml:lang="en">22614</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017665" xml:lang="en">1017665</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017695" xml:lang="en">1017695</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0652" xml:lang="en">ADV-2007-0652</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?uid=swg1IY94817" xml:lang="en">IY94817</vuln:reference>
    </vuln:references>
    <vuln:summary>Certain setuid DB2 binaries in IBM DB2 before 9 Fix Pack 2 for Linux and Unix allow local users to overwrite arbitrary files via a symlink attack on the DB2DIAG.LOG temporary file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1028">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:barry_jaspan:image_pager:4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:barry_jaspan:image_pager:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:barry_jaspan:image_pager:4.7</vuln:product>
      <vuln:product>cpe:/a:barry_jaspan:image_pager:5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1028</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:34.500-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://drupal.org/node/119293" xml:lang="en">http://drupal.org/node/119293</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22586" xml:lang="en">22586</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0636" xml:lang="en">ADV-2007-0636</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32539" xml:lang="en">imagepager-img-xss(32539)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the Barry Jaspan Image Pager 4.7.x-1.x-dev and 5.x-1.x-dev before 2007-02-08 module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to HTML entities and the IMG element.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1029">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:quicksoft:easymail_objects:6.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:quicksoft:easymail_objects:6.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1029</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:25.423-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://security-assessment.com/files/advisories/easymail_advisory.pdf" xml:lang="en">http://security-assessment.com/files/advisories/easymail_advisory.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2277" xml:lang="en">2277</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460237/100/0/threaded" xml:lang="en">20070215 EasyMail Objects v6.5 Connect Method Stack Overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22583" xml:lang="en">22583</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0634" xml:lang="en">ADV-2007-0634</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32540" xml:lang="en">easymailobjects-connect-bo(32540)</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in the Connect method in the IMAP4 component in Quiksoft EasyMail Objects before 6.5 allows remote attackers to execute arbitrary code via a long host name.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1030">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:niels_provos:libevent:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:niels_provos:libevent:1.2a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:niels_provos:libevent:1.2</vuln:product>
      <vuln:product>cpe:/a:niels_provos:libevent:1.2a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1030</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:26.327-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://monkey.org/~provos/libevent/" xml:lang="en">http://monkey.org/~provos/libevent/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2268" xml:lang="en">2268</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460530/100/0/threaded" xml:lang="en">20070219 Remote DoS in libevent DNS parsing &lt;= 1.2a</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22606" xml:lang="en">22606</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0647" xml:lang="en">ADV-2007-0647</vuln:reference>
    </vuln:references>
    <vuln:summary>Niels Provos libevent 1.2 and 1.2a allows remote attackers to cause a denial of service (infinite loop) via a DNS response containing a label pointer that references its own offset.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1031">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:spoonlabs:vivvo_article_management_cms:3.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:spoonlabs:vivvo_article_management_cms:3.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1031</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:44.423-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22600" xml:lang="en">22600</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32553" xml:lang="en">vivvo-dbconn-file-include(32553)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3326" xml:lang="en">3326</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in include/db_conn.php in SpoonLabs Vivvo Article Management CMS 3.4 allows remote attackers to include and execute arbitrary local files via the root parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1032">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:0.60"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:0.65"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:0.70"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:0.80"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:0.80a"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:0.85"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:0.86"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:0.87"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:0.90"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:0.95"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:0.666"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.0.1a"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.1.4a"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.2.5a"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.2.5b"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.3.9pl1"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.3.12"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.3.13"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.3.14"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.4.0a"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.4.8"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.4.9"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.4.10"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.4.11"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.5.9"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.6.7"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.6.8"/>
        <cpe-lang:fact-ref name="cpe:/a:phpmyfaq:phpmyfaq:1.6.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:0.60</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:0.65</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:0.70</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:0.80</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:0.80a</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:0.85</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:0.86</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:0.87</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:0.90</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:0.95</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:0.666</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.0</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.0.1</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.0.1a</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.1.0</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.1.1</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.1.2</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.1.3</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.1.4</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.1.4a</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.1.5</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.2.0</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.2.1</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.2.2</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.2.3</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.2.4</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.2.5</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.2.5a</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.2.5b</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.3.0</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.3.1</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.3.2</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.3.3</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.3.4</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.3.5</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.3.6</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.3.7</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.3.8</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.3.9</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.3.9pl1</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.3.10</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.3.11</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.3.12</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.3.13</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.3.14</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.4.0</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.4.0a</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.4.1</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.4.2</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.4.3</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.4.4</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.4.5</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.4.6</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.4.7</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.4.8</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.4.9</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.4.10</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.4.11</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.5.0</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.5.1</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.5.2</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.5.3</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.5.4</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.5.5</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.5.6</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.5.7</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.5.8</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.5.9</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.6.0</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.6.1</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.6.2</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.6.3</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.6.4</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.6.5</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.6.6</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.6.7</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.6.8</vuln:product>
      <vuln:product>cpe:/a:phpmyfaq:phpmyfaq:1.6.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1032</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:34.657-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.phpmyfaq.de/advisory_2007-02-18.php" xml:lang="en">http://www.phpmyfaq.de/advisory_2007-02-18.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32573" xml:lang="en">phpmyfaq-php-file-upload(32573)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in phpMyFAQ 1.6.9 and earlier, when register_globals is enabled, allows remote attackers to "gain the privilege for uploading files on the server."</vuln:summary>
  </entry>
  <entry id="CVE-2007-1033">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:drupal:secure_site_module:4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:secure_site_module:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:drupal:secure_site_module:4.7</vuln:product>
      <vuln:product>cpe:/a:drupal:secure_site_module:5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1033</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:34.720-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://drupal.org/node/119619" xml:lang="en">http://drupal.org/node/119619</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0637" xml:lang="en">ADV-2007-0637</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32538" xml:lang="en">securesite-url-security-bypass(32538)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the Secure site 4.7.x-1.x-dev and 5.x-1.x-dev module for Drupal allows remote attackers to bypass access restrictions via a crafted URL.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1034">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:php-nuke:emporium_module:2.3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php-nuke:emporium_module:2.3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1034</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T14:05:28.377-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2018-10-18T09:29:16.883-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22612" xml:lang="en">22612</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0661" xml:lang="en">ADV-2007-0661</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/23699" xml:lang="en">emporium-modules-sql-injection(23699)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3334" xml:lang="en">3334</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in the category file in modules.php in the Emporium 2.3.0 and earlier module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the category_id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1035">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:drupal:audio_module"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:getid3:1.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:drupal:mediafield_module"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:drupal:audio_module</vuln:product>
      <vuln:product>cpe:/a:drupal:getid3:1.7.1</vuln:product>
      <vuln:product>cpe:/a:drupal:mediafield_module</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1035</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:34.813-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://blamcast.net/articles/highly-critical-security-flaws-in-drupal-audio-module" xml:lang="en">http://blamcast.net/articles/highly-critical-security-flaws-in-drupal-audio-module</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://drupal.org/node/119385" xml:lang="en">http://drupal.org/node/119385</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22587" xml:lang="en">22587</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0635" xml:lang="en">ADV-2007-0635</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32542" xml:lang="en">drupal-getid3-code-execution(32542)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in certain demonstration scripts in getID3 1.7.1, as used in the Mediafield and Audio modules for Drupal, allows remote attackers to read and delete arbitrary files, list arbitrary directories, and write to empty files or .mp3 files via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1036">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:jboss:jboss_application_server"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:jboss:jboss_application_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1036</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:27.030-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://wiki.jboss.org/wiki/Wiki.jsp?page=SecureJBoss" xml:lang="en">http://wiki.jboss.org/wiki/Wiki.jsp?page=SecureJBoss</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://wiki.jboss.org/wiki/Wiki.jsp?page=SecureTheJmxConsole" xml:lang="en">http://wiki.jboss.org/wiki/Wiki.jsp?page=SecureTheJmxConsole</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/632656" xml:lang="en">VU#632656</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460597/100/0/threaded" xml:lang="en">20070220 Jboss vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460605/100/0/threaded" xml:lang="en">20070220 Re: Jboss vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460695/100/0/threaded" xml:lang="en">20070220 Re: Jboss vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017677" xml:lang="en">1017677</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32596" xml:lang="en">jboss-admin-unauth-access(32596)</vuln:reference>
    </vuln:references>
    <vuln:summary>The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allows remote attackers to bypass authentication and gain administrative access via direct requests.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1037">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:rsbr-software:news_file_grabber:4.1.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rsbr-software:news_file_grabber:4.1.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1037</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:34.923-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22617" xml:lang="en">22617</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0662" xml:lang="en">ADV-2007-0662</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32577" xml:lang="en">newsfilegrabber-nzb-bo(32577)</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in News File Grabber 4.1.0.1 and earlier allows remote attackers to execute arbitrary code via a .nzb file with a long subject field.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1038">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:shemes.com:grabit:1.5.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:shemes.com:grabit:1.5.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1038</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:34.970-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22619" xml:lang="en">22619</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0664" xml:lang="en">ADV-2007-0664</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32579" xml:lang="en">grabit-nzb-dos(32579)</vuln:reference>
    </vuln:references>
    <vuln:summary>Shemes.com Grabit 1.5.3, and possibly earlier, allows remote attackers to cause a denial of service (application crash) via a .nzb file with a subject field containing ';' (semicolon) characters.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1039">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:peanutkb:peanut_knowledge_base:0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:peanutkb:peanut_knowledge_base:0.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:peanutkb:peanut_knowledge_base:0.0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:peanutkb:peanut_knowledge_base:0.0.1</vuln:product>
      <vuln:product>cpe:/a:peanutkb:peanut_knowledge_base:0.0.2</vuln:product>
      <vuln:product>cpe:/a:peanutkb:peanut_knowledge_base:0.0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1039</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:35.063-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?group_id=157653&amp;release_id=483888" xml:lang="en">http://sourceforge.net/project/shownotes.php?group_id=157653&amp;release_id=483888</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22628" xml:lang="en">22628</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0666" xml:lang="en">ADV-2007-0666</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32574" xml:lang="en">peanutkb-multiple-unspecified(32574)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Peanut Knowledge Base (PeanutKB) 0.0.3 and earlier has unknown impact and attack vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1040">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:xpression_news:xpression_news:1.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xpression_news:xpression_news:1.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1040</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:44.533-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22609" xml:lang="en">22609</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0645" xml:lang="en">ADV-2007-0645</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32560" xml:lang="en">xnews-archives-news-directory-traversal(32560)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3332" xml:lang="en">3332</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in archives.php in Xpression News (X-News) 1.0.1 allows remote attackers to include arbitrary files or obtain sensitive information via a .. (dot dot) in the xnews-template parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1041">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sandh:news_rover:12.1:rev1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sandh:news_rover:12.1:rev1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1041</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:44.597-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22618" xml:lang="en">22618</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0663" xml:lang="en">ADV-2007-0663</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32576" xml:lang="en">newsrover-nzb-bo(32576)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3342" xml:lang="en">3342</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple stack-based buffer overflows in S&amp;H Computer Systems News Rover 12.1 Rev 1 allow remote attackers to execute arbitrary code via a .nzb file with a long (1) group or (2) subject string.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1042">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:xpression_news:xpression_news:1.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xpression_news:xpression_news:1.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1042</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:35.220-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32560" xml:lang="en">xnews-archives-news-directory-traversal(32560)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in news.php in Xpression News (X-News) 1.0.1, when magic_quotes_gpc is disabled, allows remote attackers to include arbitrary files or obtain sensitive information via a .. (dot dot) in the xnews-template parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1043">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.9"/>
          <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux"/>
          <cpe-lang:fact-ref name="cpe:/o:hp:tru64:5.1b_pk2_bl22"/>
          <cpe-lang:fact-ref name="cpe:/o:ibm:aix"/>
          <cpe-lang:fact-ref name="cpe:/o:ibm:os2"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_95"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98::gold"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98se"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_me"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold"/>
          <cpe-lang:fact-ref name="cpe:/o:santa_cruz_operation:sco_unix"/>
          <cpe-lang:fact-ref name="cpe:/o:sun:solaris"/>
          <cpe-lang:fact-ref name="cpe:/o:windriver:bsdos"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:ezboo:webstats:3.0.3"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ezboo:webstats:3.0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1043</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:27.717-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://forums.avenir-geopolitique.net/viewtopic.php?t=2674" xml:lang="en">http://forums.avenir-geopolitique.net/viewtopic.php?t=2674</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2275" xml:lang="en">2275</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460325/100/0/threaded" xml:lang="en">20070215 Ezboo webstats acces to sensitive files</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22590" xml:lang="en">22590</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32563" xml:lang="en">ezboo-update-unauthorized-access(32563)</vuln:reference>
    </vuln:references>
    <vuln:summary>Ezboo webstats, possibly 3.0.3, allows remote attackers to bypass authentication and gain access via a direct request to (1) update.php and (2) config.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1044">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:pearson_education:powerschool:4.3.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:pearson_education:powerschool:4.3.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1044</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:28.140-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2276" xml:lang="en">2276</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460533/100/0/threaded" xml:lang="en">20070219 Powerschool 404 Admin Exposure</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/484569/100/200/threaded" xml:lang="en">20071204 Re: Powerschool 404 Admin Exposure</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22611" xml:lang="en">22611</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32569" xml:lang="en">powerschool-js-information-disclosure(32569)</vuln:reference>
    </vuln:references>
    <vuln:summary>Pearson Education PowerSchool 4.3.6 allows remote attackers to list the contents of the admin folder via a URI composed of the admin/ directory name and an arbitrary filename ending in ".js."  NOTE: it was later reported that this issue had been addressed by 5.1.2.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1045">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:malbum:malbum:0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:malbum:malbum:0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1045</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:28.547-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://forums.avenir-geopolitique.net/viewtopic.php?t=2677" xml:lang="en">http://forums.avenir-geopolitique.net/viewtopic.php?t=2677</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2272" xml:lang="en">2272</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460402/100/0/threaded" xml:lang="en">20070217 mAlbum v0.3 admin by default user/pass</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32562" xml:lang="en">malbum-default-admin-account(32562)</vuln:reference>
    </vuln:references>
    <vuln:summary>mAlbum 0.3 has default accounts (1) "login"/"pass" for its administrative account and (2) "dqsfg"/"sdfg", which allows remote attackers to gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1046">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:dem_trac:dem_trac"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:dem_trac:dem_trac</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1046</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:28.813-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://forums.avenir-geopolitique.net/viewtopic.php?t=2673" xml:lang="en">http://forums.avenir-geopolitique.net/viewtopic.php?t=2673</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2271" xml:lang="en">2271</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460306/100/0/threaded" xml:lang="en">20070215 Dem_trac acces to log file wihtout authentification</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32566" xml:lang="en">demtrac-ancsit-information-disclosure(32566)</vuln:reference>
    </vuln:references>
    <vuln:summary>Dem_trac allows remote attackers to read log file contents via a direct request for /anc_sit.txt.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1047">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:distributed_checksum_clearinghouse:dcc:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:distributed_checksum_clearinghouse:dcc:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:distributed_checksum_clearinghouse:dcc:1.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:distributed_checksum_clearinghouse:dcc:1.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:distributed_checksum_clearinghouse:dcc:1.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:distributed_checksum_clearinghouse:dcc:1.3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:distributed_checksum_clearinghouse:dcc:1.3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:distributed_checksum_clearinghouse:dcc:1.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:distributed_checksum_clearinghouse:dcc:1.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:distributed_checksum_clearinghouse:dcc:1.3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:distributed_checksum_clearinghouse:dcc:1.3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:distributed_checksum_clearinghouse:dcc:1.3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:distributed_checksum_clearinghouse:dcc:1.3.12"/>
        <cpe-lang:fact-ref name="cpe:/a:distributed_checksum_clearinghouse:dcc:1.3.13"/>
        <cpe-lang:fact-ref name="cpe:/a:distributed_checksum_clearinghouse:dcc:1.3.14"/>
        <cpe-lang:fact-ref name="cpe:/a:distributed_checksum_clearinghouse:dcc:1.3.15"/>
        <cpe-lang:fact-ref name="cpe:/a:distributed_checksum_clearinghouse:dcc:1.3.16"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:distributed_checksum_clearinghouse:dcc:1.3</vuln:product>
      <vuln:product>cpe:/a:distributed_checksum_clearinghouse:dcc:1.3.1</vuln:product>
      <vuln:product>cpe:/a:distributed_checksum_clearinghouse:dcc:1.3.2</vuln:product>
      <vuln:product>cpe:/a:distributed_checksum_clearinghouse:dcc:1.3.3</vuln:product>
      <vuln:product>cpe:/a:distributed_checksum_clearinghouse:dcc:1.3.4</vuln:product>
      <vuln:product>cpe:/a:distributed_checksum_clearinghouse:dcc:1.3.5</vuln:product>
      <vuln:product>cpe:/a:distributed_checksum_clearinghouse:dcc:1.3.6</vuln:product>
      <vuln:product>cpe:/a:distributed_checksum_clearinghouse:dcc:1.3.7</vuln:product>
      <vuln:product>cpe:/a:distributed_checksum_clearinghouse:dcc:1.3.8</vuln:product>
      <vuln:product>cpe:/a:distributed_checksum_clearinghouse:dcc:1.3.9</vuln:product>
      <vuln:product>cpe:/a:distributed_checksum_clearinghouse:dcc:1.3.10</vuln:product>
      <vuln:product>cpe:/a:distributed_checksum_clearinghouse:dcc:1.3.11</vuln:product>
      <vuln:product>cpe:/a:distributed_checksum_clearinghouse:dcc:1.3.12</vuln:product>
      <vuln:product>cpe:/a:distributed_checksum_clearinghouse:dcc:1.3.13</vuln:product>
      <vuln:product>cpe:/a:distributed_checksum_clearinghouse:dcc:1.3.14</vuln:product>
      <vuln:product>cpe:/a:distributed_checksum_clearinghouse:dcc:1.3.15</vuln:product>
      <vuln:product>cpe:/a:distributed_checksum_clearinghouse:dcc:1.3.16</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1047</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:51:12.313-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.rhyolite.com/anti-spam/dcc/CHANGES" xml:lang="en">http://www.rhyolite.com/anti-spam/dcc/CHANGES</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22622" xml:lang="en">22622</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0654" xml:lang="en">ADV-2007-0654</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Distributed Checksum Clearinghouse (DCC) before 1.3.51 allows remote attackers to delete or add hosts in /var/dcc/maps.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1048">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpbb_wordsearch:phpbb_wordsearch"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpbb_wordsearch:phpbb_wordsearch</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1048</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:29.173-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2280" xml:lang="en">2280</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460338/100/0/threaded" xml:lang="en">20070216 phpbb_wordsearch &lt; = RFi Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32551" xml:lang="en">phpbbwordsearch-rebuildsearch-file-include(32551)</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in admin_rebuild_search.php in phpbb_wordsearch allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1049">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:0.6.2:beta_2"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:0.6.2.1:beta_2"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:0.71"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:1.5.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:1.5.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.0.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:gentoo:linux"/>
          <cpe-lang:fact-ref name="cpe:/o:gentoo:linux:1.4"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:1.2"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:gentoo:linux"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:1.2.1"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wordpress:wordpress:0.6.2:beta_2</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:0.6.2.1:beta_2</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:0.7</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:0.71</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:1.2</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:1.2.1</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:1.2.2</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:1.5</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:1.5.1</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:1.5.1.2</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:1.5.1.3</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:1.5.2</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.1</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.2</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.3</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.4</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.5</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.6</vuln:product>
      <vuln:product>cpe:/a:wordpress:wordpress:2.0.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1049</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:51:12.547-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://downloads.securityfocus.com/vulnerabilities/exploits/22534.html" xml:lang="en">http://downloads.securityfocus.com/vulnerabilities/exploits/22534.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://trac.wordpress.org/changeset/4876" xml:lang="en">http://trac.wordpress.org/changeset/4876</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://trac.wordpress.org/changeset/4877" xml:lang="en">http://trac.wordpress.org/changeset/4877</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://trac.wordpress.org/ticket/3781" xml:lang="en">http://trac.wordpress.org/ticket/3781</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200703-23.xml" xml:lang="en">GLSA-200703-23</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22534" xml:lang="en">22534</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0741" xml:lang="en">ADV-2007-0741</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the wp_explain_nonce function in the nonce AYS functionality (wp-includes/functions.php) for WordPress 2.0 before 2.0.9 and 2.1 before 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the file parameter to wp-admin/templates.php, and possibly other vectors involving the action variable.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1050">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:abledesign:mycalendar"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:abledesign:mycalendar</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1050</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:29.470-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://forums.avenir-geopolitique.net/viewtopic.php?t=2686" xml:lang="en">http://forums.avenir-geopolitique.net/viewtopic.php?t=2686</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2270" xml:lang="en">2270</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460598/100/0/threaded" xml:lang="en">20070219 MyCalendar multiple XSS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22635" xml:lang="en">22635</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0679" xml:lang="en">ADV-2007-0679</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32581" xml:lang="en">mycalendar-index-xss(32581)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in index.php in AbleDesign MyCalendar allow remote attackers to inject arbitrary web script or HTML via (1) the go parameter, (2) the keyword parameter in the search menu (go=search), or (3) the username or (4) the password in a go=Login action.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1051">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:comodo:comodo_firewall_pro:2.4.17.183"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:comodo:comodo_firewall_pro:2.4.17.183</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1051</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:30.093-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052461.html" xml:lang="en">20070215 Comodo DLL injection via weak hash function exploitation Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2279" xml:lang="en">2279</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.matousec.com/info/advisories/Comodo-DLL-injection-via-weak-hash-function-exploitation.php" xml:lang="en">http://www.matousec.com/info/advisories/Comodo-DLL-injection-via-weak-hash-function-exploitation.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460209/100/100/threaded" xml:lang="en">20070215 Comodo DLL injection via weak hash function exploitation Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32530" xml:lang="en">comodofirewallpro-crc32-security-bypass(32530)</vuln:reference>
    </vuln:references>
    <vuln:summary>Comodo Firewall Pro (formerly Comodo Personal Firewall) 2.4.17.183 and earlier uses a weak cryptographic hashing function (CRC32) to identify trusted modules, which allows local users to bypass security protections by substituting modified modules that have the same CRC32 value.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1052">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:pblang:pblang:4.60"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:pblang:pblang:4.60</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1052</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:30.423-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://attrition.org/pipermail/vim/2007-February/001356.html" xml:lang="en">20070216 PBLang 4.60 &lt;= (index.php) Remote File Include Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2269" xml:lang="en">2269</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460315/100/0/threaded" xml:lang="en">20070216 PBLang 4.60 &lt;= (index.php) Remote File Include Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>** DISPUTED **  PHP remote file inclusion vulnerability in index.php in PBLang (PBL) 4.60 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the dbpath parameter, a different vector than CVE-2006-5062.  NOTE: this issue has been disputed by a reliable third party for 4.65, stating that the dbpath variable is initialized in an included file that is created upon installation.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1053">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:warped_systems:phpxmms:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:warped_systems:phpxmms:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1053</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:30.593-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://attrition.org/pipermail/vim/2007-February/001365.html" xml:lang="en">20070220 false: phpXmms 1.0 (tcmdp) Remote File Include Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2273" xml:lang="en">2273</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460618/100/0/threaded" xml:lang="en">20070220 phpXmms 1.0 (tcmdp) Remote File Include Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:summary>** DISPUTED **  Multiple PHP remote file inclusion vulnerabilities in phpXmms 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the tcmdp parameter to (1) phpxmmsb.php or (2) phpxmmst.php.  NOTE: this issue has been disputed by a reliable third party, stating that the tcmdp variable is initialized by config.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1054">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.8.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.8.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1054</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:30.780-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://attrition.org/pipermail/vim/2007-February/001367.html" xml:lang="en">20070221 [unsure] MediaWiki Cross-site Scripting</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2274" xml:lang="en">2274</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=487921&amp;group_id=34373" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=487921&amp;group_id=34373</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_9_3/phase3/RELEASE-NOTES" xml:lang="en">http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_9_3/phase3/RELEASE-NOTES</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.bugsec.com/articles.php?Security=24" xml:lang="en">http://www.bugsec.com/articles.php?Security=24</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460596/100/0/threaded" xml:lang="en">20070220 MediaWiki Cross-site Scripting</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0678" xml:lang="en">ADV-2007-0678</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32586" xml:lang="en">mediawiki-index-xss(32586)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the AJAX features in index.php in MediaWiki 1.6.x through 1.9.2, when $wgUseAjax is enabled, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded value of the rs parameter, which is processed by Internet Explorer.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1055">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.8.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mediawiki:mediawiki:1.9.0:rc1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.8.2</vuln:product>
      <vuln:product>cpe:/a:mediawiki:mediawiki:1.9.0:rc1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1055</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-19T14:08:48.990-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2018-10-18T09:48:01.087-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2274" xml:lang="en">2274</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_9_0/phase3/RELEASE-NOTES" xml:lang="en">http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_9_0/phase3/RELEASE-NOTES</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.bugsec.com/articles.php?Security=24" xml:lang="en">http://www.bugsec.com/articles.php?Security=24</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460596/100/0/threaded" xml:lang="en">20070220 MediaWiki Cross-site Scripting</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32586" xml:lang="en">mediawiki-index-xss(32586)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the AJAX features in index.php in MediaWiki 1.9.x before 1.9.0rc2, and 1.8.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the rs parameter.  NOTE: this issue might be a duplicate of CVE-2007-0177.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1056">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.3_build_34685"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vmware:workstation:5.5.3_build_34685</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1056</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:31.577-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2281" xml:lang="en">2281</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460664/100/0/threaded" xml:lang="en">20070219 VMware Workstation multiple denial of service and isolation manipulation vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461807/100/0/threaded" xml:lang="en">20070303 Re: VMware Workstation multiple denial of service and isolation manipulation vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:summary>VMware Workstation 5.5.3 build 34685 does not provide per-user restrictions on certain privileged actions, which allows local users to perform restricted operations such as changing system time, accessing hardware components, and stopping the "VMware tools service" service. NOTE: exploitation is simplified via (1) weak file permissions (Users = Read &amp; Execute) for %PROGRAMFILES%\VMware; and weak registry key permissions (access by Users) for (2) vmmouse, (3) vmscsi, (4) VMTools, (5) vmx_svga, and (6) vmxnet in HKLM\SYSTEM\CurrentControlSet\Services\; which allows local users to perform various privileged actions outside of the guest OS by executing certain files under %PROGRAMFILES%\VMware\VMware Tools, as demonstrated by (a) VMControlPanel.cpl and (b) vmwareservice.exe.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1057">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/h:nortel:alteon_2424_application_switch:23.2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/h:nortel:ssl_vpn_module_1000"/>
          <cpe-lang:fact-ref name="cpe:/h:nortel:vpn_gateway_3070"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:nortel:net_direct_client:6.0.4::linux"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nortel:net_direct_client:6.0.4::linux</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1057</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:44.657-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://spoofed.org/blog/archive/2007/02/nortel_vpn_unix_client_local_root_compromise.html" xml:lang="en">http://spoofed.org/blog/archive/2007/02/nortel_vpn_unix_client_local_root_compromise.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22632" xml:lang="en">22632</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017678" xml:lang="en">1017678</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0671" xml:lang="en">ADV-2007-0671</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www116.nortelnetworks.com/pub/repository/CLARIFY/DOCUMENT/2007/08/021886-01.pdf" xml:lang="en">http://www116.nortelnetworks.com/pub/repository/CLARIFY/DOCUMENT/2007/08/021886-01.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www130.nortelnetworks.com/go/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=540071" xml:lang="en">http://www130.nortelnetworks.com/go/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=540071</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32597" xml:lang="en">netdirect-permissions-privilege-escalation(32597)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3356" xml:lang="en">3356</vuln:reference>
    </vuln:references>
    <vuln:summary>The Net Direct client for Linux before 6.0.5 in Nortel Application Switch 2424, VPN 3050 and 3070, and SSL VPN Module 1000 extracts and executes files with insecure permissions, which allows local users to exploit a race condition to replace a world-writable file in /tmp/NetClient and cause another user to execute arbitrary code when attempting to execute this client, as demonstrated by replacing /tmp/NetClient/client.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1058">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:online_web_building:online_web_building:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:online_web_building:online_web_building:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1058</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:06.833-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0674" xml:lang="en">ADV-2007-0674</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32583" xml:lang="en">userpages2-page-sql-injection(32583)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3339" xml:lang="en">3339</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in user_pages/page.asp in Online Web Building 2.0 allows remote attackers to execute arbitrary SQL commands via the art_id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1059">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ultimate_fun_book:ultimate_fun_book:1.02"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ultimate_fun_book:ultimate_fun_book:1.02</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1059</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:06.893-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22633" xml:lang="en">22633</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0675" xml:lang="en">ADV-2007-0675</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32584" xml:lang="en">ultimatefunbook-function-file-include(32584)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3336" xml:lang="en">3336</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in function.php in Ultimate Fun Book 1.02 allows remote attackers to execute arbitrary PHP code via a URL in the gbpfad parameter.  NOTE: some sources mention "Ultimate Fun Board," but this appears to be an error.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1060">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:interspire:sendstudio:2004.14"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:interspire:sendstudio:2004.14</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1060</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:31.827-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://advisories.echo.or.id/adv/adv66-K-159-2007.txt" xml:lang="en">http://advisories.echo.or.id/adv/adv66-K-159-2007.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460964/100/0/threaded" xml:lang="en">20070221 [ECHO_ADV_66$2007] SendStudio &lt;= 2004.14 Remote File Inclusion Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461019/100/0/threaded" xml:lang="en">20070223 Re: [ECHO_ADV_66$2007] SendStudio &lt;= 2004.14 Remote File Inclusion Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22642" xml:lang="en">22642</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0672" xml:lang="en">ADV-2007-0672</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32602" xml:lang="en">sendstudio-rootdir-file-include(32602)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3348" xml:lang="en">3348</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple PHP remote file inclusion vulnerabilities in Interspire SendStudio 2004.14 and earlier, when register_globals and allow_fopenurl are enabled, allow remote attackers to execute arbitrary PHP code via a URL in the ROOTDIR parameter to (1) createemails.inc.php and (2) send_emails.inc.php in /admin/includes/.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1061">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:francisco_burzi:php-nuke:8.0_final"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:francisco_burzi:php-nuke:8.0_final</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1061</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T19:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:32.423-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052570.html" xml:lang="en">20070220 Blind sql injection attack in INSERT syntax on PHP-nuke &lt;=8.0 Final</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461148/100/0/threaded" xml:lang="en">20070224 Blind sql injection attack in INSERT syntax on PHP-nuke &lt;=8.0 Final</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22638" xml:lang="en">22638</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0673" xml:lang="en">ADV-2007-0673</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32607" xml:lang="en">phpnuke-index-sql-injection(32607)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3346" xml:lang="en">3346</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in index.php in Francisco Burzi PHP-Nuke 8.0 Final and earlier, when the "HTTP Referers" block is enabled, allows remote attackers to execute arbitrary SQL commands via the HTTP Referer header (HTTP_REFERER variable).</vuln:summary>
  </entry>
  <entry id="CVE-2007-1062">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:cisco:unified_ip_conference_station_7935_firmware:3.2%2815%29"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/h:cisco:unified_ip_conference_station_7935:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:cisco:unified_ip_conference_station_firmware_7936:3.3%2812%29"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/h:cisco:unified_ip_conference_station_7936:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:cisco:unified_ip_conference_station_7935_firmware:3.2%2815%29</vuln:product>
      <vuln:product>cpe:/o:cisco:unified_ip_conference_station_firmware_7936:3.3%2812%29</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1062</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-05-23T12:13:16.810-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2019-05-22T10:59:07.773-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017680" xml:lang="en">1017680</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-air-20070221-phone.shtml" xml:lang="en">20070221 Identifying and Mitigating Exploitation of Cisco Unified IP Conference Station and IP Phone Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20070221-phone.shtml" xml:lang="en">20070221 Cisco Unified IP Conference Station and IP Phone Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22647" xml:lang="en">22647</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0688" xml:lang="en">ADV-2007-0688</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32623" xml:lang="en">cisco-unified-ip-conference-url-auth-bypass(32623)</vuln:reference>
    </vuln:references>
    <vuln:summary>The Cisco Unified IP Conference Station 7935 3.2(15) and earlier, and Station 7936 3.3(12) and earlier does not properly handle administrator HTTP sessions, which allows remote attackers to bypass authentication controls via a direct URL request to the administrative HTTP interface for a limited time</vuln:summary>
  </entry>
  <entry id="CVE-2007-1063">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:cisco:unified_ip_phone_firmware_7906g:8.0%284%29:sr1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/h:cisco:unified_ip_phone_7906g:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:cisco:unified_ip_phone_firmware_7911g:8.0%284%29:sr1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/h:cisco:unified_ip_phone_7911g:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:cisco:unified_ip_phone_firmware_7941g:8.0%284%29:sr1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/h:cisco:unified_ip_phone_7941g:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:cisco:unified_ip_phone_firmware_7961g:8.0%284%29:sr1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/h:cisco:unified_ip_phone_7961g:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:cisco:unified_ip_phone_firmware_7970g:8.0%284%29:sr1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/h:cisco:unified_ip_phone_7970g:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:cisco:unified_ip_phone_firmware_7971g:8.0%284%29:sr1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/h:cisco:unified_ip_phone_7971g:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:cisco:unified_ip_phone_firmware_7906g:8.0%284%29:sr1</vuln:product>
      <vuln:product>cpe:/o:cisco:unified_ip_phone_firmware_7911g:8.0%284%29:sr1</vuln:product>
      <vuln:product>cpe:/o:cisco:unified_ip_phone_firmware_7941g:8.0%284%29:sr1</vuln:product>
      <vuln:product>cpe:/o:cisco:unified_ip_phone_firmware_7961g:8.0%284%29:sr1</vuln:product>
      <vuln:product>cpe:/o:cisco:unified_ip_phone_firmware_7970g:8.0%284%29:sr1</vuln:product>
      <vuln:product>cpe:/o:cisco:unified_ip_phone_firmware_7971g:8.0%284%29:sr1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1063</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-05-23T12:15:42.703-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2019-05-22T11:08:01.240-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-798"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-air-20070221-phone.shtml" xml:lang="en">20070221 Identifying and Mitigating Exploitation of Cisco Unified IP Conference Station and IP Phone Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20070221-phone.shtml" xml:lang="en">20070221 Cisco Unified IP Conference Station and IP Phone Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22647" xml:lang="en">22647</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017681" xml:lang="en">1017681</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0689" xml:lang="en">ADV-2007-0689</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32627" xml:lang="en">cisco-unified-ip-phone-default-user-account(32627)</vuln:reference>
    </vuln:references>
    <vuln:summary>The SSH server in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G, with firmware 8.0(4)SR1 and earlier, uses a hard-coded username and password, which allows remote attackers to access the device.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1064">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cisco:secure_services_client:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:secure_services_client:4.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:secure_services_client:4.0.51"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:security_agent:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:security_agent:5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:trust_agent:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:trust_agent:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:trust_agent:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:trust_agent:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:meetinghouse:aegis_secureconnect_client:windows_platform"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cisco:secure_services_client:4.0</vuln:product>
      <vuln:product>cpe:/a:cisco:secure_services_client:4.0.5</vuln:product>
      <vuln:product>cpe:/a:cisco:secure_services_client:4.0.51</vuln:product>
      <vuln:product>cpe:/a:cisco:security_agent:5.0</vuln:product>
      <vuln:product>cpe:/a:cisco:security_agent:5.1</vuln:product>
      <vuln:product>cpe:/a:cisco:trust_agent:1.0</vuln:product>
      <vuln:product>cpe:/a:cisco:trust_agent:2.0</vuln:product>
      <vuln:product>cpe:/a:cisco:trust_agent:2.0.1</vuln:product>
      <vuln:product>cpe:/a:cisco:trust_agent:2.1</vuln:product>
      <vuln:product>cpe:/a:meetinghouse:aegis_secureconnect_client:windows_platform</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1064</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:36.297-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20070221-supplicant.shtml" xml:lang="en">20070221 Multiple Vulnerabilities in 802.1X Supplicant</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22648" xml:lang="en">22648</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017683" xml:lang="en">1017683</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017684" xml:lang="en">1017684</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0690" xml:lang="en">ADV-2007-0690</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32621" xml:lang="en">cisco-cssc-help-privilege-escalation(32621)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client do not drop privileges when the help facility in the supplicant GUI is invoked, which allows local users to gain privileges, aka CSCsf14120.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1065">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cisco:secure_services_client:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:secure_services_client:4.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:secure_services_client:4.0.51"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:security_agent:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:security_agent:5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:trust_agent:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:trust_agent:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:trust_agent:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:trust_agent:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:meetinghouse:aegis_secureconnect_client:windows_platform"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cisco:secure_services_client:4.0</vuln:product>
      <vuln:product>cpe:/a:cisco:secure_services_client:4.0.5</vuln:product>
      <vuln:product>cpe:/a:cisco:secure_services_client:4.0.51</vuln:product>
      <vuln:product>cpe:/a:cisco:security_agent:5.0</vuln:product>
      <vuln:product>cpe:/a:cisco:security_agent:5.1</vuln:product>
      <vuln:product>cpe:/a:cisco:trust_agent:1.0</vuln:product>
      <vuln:product>cpe:/a:cisco:trust_agent:2.0</vuln:product>
      <vuln:product>cpe:/a:cisco:trust_agent:2.0.1</vuln:product>
      <vuln:product>cpe:/a:cisco:trust_agent:2.1</vuln:product>
      <vuln:product>cpe:/a:meetinghouse:aegis_secureconnect_client:windows_platform</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1065</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:36.360-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20070221-supplicant.shtml" xml:lang="en">20070221 Multiple Vulnerabilities in 802.1X Supplicant</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22648" xml:lang="en">22648</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017683" xml:lang="en">1017683</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017684" xml:lang="en">1017684</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0690" xml:lang="en">ADV-2007-0690</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32622" xml:lang="en">cisco-cssc-privilege-escalation(32622)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client allows local users to gain SYSTEM privileges via unspecified vectors in the supplicant, aka CSCsf15836.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1066">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cisco:secure_services_client:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:secure_services_client:4.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:secure_services_client:4.0.51"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:security_agent:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:security_agent:5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:trust_agent:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:trust_agent:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:trust_agent:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:trust_agent:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:meetinghouse:aegis_secureconnect_client:windows_platform"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cisco:secure_services_client:4.0</vuln:product>
      <vuln:product>cpe:/a:cisco:secure_services_client:4.0.5</vuln:product>
      <vuln:product>cpe:/a:cisco:secure_services_client:4.0.51</vuln:product>
      <vuln:product>cpe:/a:cisco:security_agent:5.0</vuln:product>
      <vuln:product>cpe:/a:cisco:security_agent:5.1</vuln:product>
      <vuln:product>cpe:/a:cisco:trust_agent:1.0</vuln:product>
      <vuln:product>cpe:/a:cisco:trust_agent:2.0</vuln:product>
      <vuln:product>cpe:/a:cisco:trust_agent:2.0.1</vuln:product>
      <vuln:product>cpe:/a:cisco:trust_agent:2.1</vuln:product>
      <vuln:product>cpe:/a:meetinghouse:aegis_secureconnect_client:windows_platform</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1066</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:36.423-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20070221-supplicant.shtml" xml:lang="en">20070221 Multiple Vulnerabilities in 802.1X Supplicant</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22648" xml:lang="en">22648</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017683" xml:lang="en">1017683</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017684" xml:lang="en">1017684</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0690" xml:lang="en">ADV-2007-0690</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32625" xml:lang="en">cisco-cssc-dacl-privilege-escalation(32625)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client use an insecure default Discretionary Access Control Lists (DACL) for the connection client GUI, which allows local users to gain privileges by injecting "a thread under ConnectionClient.exe," aka CSCsg20558.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1067">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cisco:secure_services_client:4.x"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:security_agent:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:security_agent:5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:trust_agent:1"/>
        <cpe-lang:fact-ref name="cpe:/a:meetinghouse:aegis_secureconnect_client:windows_platform"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cisco:secure_services_client:4.x</vuln:product>
      <vuln:product>cpe:/a:cisco:security_agent:5.0</vuln:product>
      <vuln:product>cpe:/a:cisco:security_agent:5.1</vuln:product>
      <vuln:product>cpe:/a:cisco:trust_agent:1</vuln:product>
      <vuln:product>cpe:/a:meetinghouse:aegis_secureconnect_client:windows_platform</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1067</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:36.487-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20070221-supplicant.shtml" xml:lang="en">20070221 Multiple Vulnerabilities in 802.1X Supplicant</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22648" xml:lang="en">22648</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017683" xml:lang="en">1017683</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017684" xml:lang="en">1017684</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0690" xml:lang="en">ADV-2007-0690</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32624" xml:lang="en">cisco-cssc-parsing-privilege-escalation(32624)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client do not properly parse commands, which allows local users to gain privileges via unspecified vectors, aka CSCsh30624.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1068">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cisco:secure_services_client:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:secure_services_client:4.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:secure_services_client:4.0.51"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:security_agent:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:security_agent:5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:trust_agent:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:trust_agent:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:trust_agent:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:trust_agent:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:meetinghouse:aegis_secureconnect_client:windows_platform"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cisco:secure_services_client:4.0</vuln:product>
      <vuln:product>cpe:/a:cisco:secure_services_client:4.0.5</vuln:product>
      <vuln:product>cpe:/a:cisco:secure_services_client:4.0.51</vuln:product>
      <vuln:product>cpe:/a:cisco:security_agent:5.0</vuln:product>
      <vuln:product>cpe:/a:cisco:security_agent:5.1</vuln:product>
      <vuln:product>cpe:/a:cisco:trust_agent:1.0</vuln:product>
      <vuln:product>cpe:/a:cisco:trust_agent:2.0</vuln:product>
      <vuln:product>cpe:/a:cisco:trust_agent:2.0.1</vuln:product>
      <vuln:product>cpe:/a:cisco:trust_agent:2.1</vuln:product>
      <vuln:product>cpe:/a:meetinghouse:aegis_secureconnect_client:windows_platform</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1068</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T20:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:36.547-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-255"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20070221-supplicant.shtml" xml:lang="en">20070221 Multiple Vulnerabilities in 802.1X Supplicant</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22648" xml:lang="en">22648</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017683" xml:lang="en">1017683</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017684" xml:lang="en">1017684</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0690" xml:lang="en">ADV-2007-0690</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32626" xml:lang="en">cisco-cssc-password-information-disclosure(32626)</vuln:reference>
    </vuln:references>
    <vuln:summary>The (1) TTLS CHAP, (2) TTLS MSCHAP, (3) TTLS MSCHAPv2, (4) TTLS PAP, (5) MD5, (6) GTC, (7) LEAP, (8) PEAP MSCHAPv2, (9) PEAP GTC, and (10) FAST authentication methods in Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client store transmitted authentication credentials in plaintext log files, which allows local users to obtain sensitive information by reading these files, aka CSCsg34423.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1069">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vmware:workstation:5.5.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1069</vuln:cve-id>
    <vuln:published-datetime>2007-05-02T15:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:32.827-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.reversemode.com/index.php?option=com_remository&amp;Itemid=2&amp;func=fileinfo&amp;id=49" xml:lang="en">http://www.reversemode.com/index.php?option=com_remository&amp;Itemid=2&amp;func=fileinfo&amp;id=49</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/467836/100/0/threaded" xml:lang="en">20070507 [Reversemode Advisory] VMware Products - GPF Denial of Service</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/467936/30/6690/threaded" xml:lang="en">20070507 VMSA-2007-0004 Multiple Denial-of-Service issues fixed</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/469011/30/6510/threaded" xml:lang="en">20070518 VMSA-2007-0004.1 Updated: Multiple Denial-of-Service issues fixed and directory traversal vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23732" xml:lang="en">23732</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018011" xml:lang="en">1018011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html#554" xml:lang="en">http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html#554</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1592" xml:lang="en">ADV-2007-1592</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33994" xml:lang="en">vmware-gpf-dos(33994)</vuln:reference>
    </vuln:references>
    <vuln:summary>The memory management in VMware Workstation before 5.5.4 allows attackers to cause a denial of service (Windows virtual machine crash) by triggering certain general protection faults (GPF).</vuln:summary>
  </entry>
  <entry id="CVE-2007-1070">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:r2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp2"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista:::32_bit"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:trend_micro:serverprotect:5.58::emc"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:serverprotect:5.58::emc"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:serverprotect:5.61::network_appliance_filer"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:serverprotect:5.62::network_appliance_filer"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:trend_micro:serverprotect:5.58::emc</vuln:product>
      <vuln:product>cpe:/a:trend_micro:serverprotect:5.61::network_appliance_filer</vuln:product>
      <vuln:product>cpe:/a:trend_micro:serverprotect:5.62::network_appliance_filer</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1070</vuln:cve-id>
    <vuln:published-datetime>2007-02-21T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:33.453-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034290" xml:lang="en">http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034290</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/349393" xml:lang="en">VU#349393</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/466609" xml:lang="en">VU#466609</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/630025" xml:lang="en">VU#630025</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/730433" xml:lang="en">VU#730433</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460686/100/0/threaded" xml:lang="en">20070220 TSRT-07-01: Trend Micro ServerProtect StCommon.dll Stack Overflow Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460690/100/0/threaded" xml:lang="en">20070220 TSRT-07-02: Trend Micro ServerProtect eng50.dll Stack Overflow Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22639" xml:lang="en">22639</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017676" xml:lang="en">1017676</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.tippingpoint.com/security/advisories/TSRT-07-01.html" xml:lang="en">http://www.tippingpoint.com/security/advisories/TSRT-07-01.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.tippingpoint.com/security/advisories/TSRT-07-02.html" xml:lang="en">http://www.tippingpoint.com/security/advisories/TSRT-07-02.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.trendmicro.com/ftp/documentation/readme/spnt_558_win_en_securitypatch1_readme.txt" xml:lang="en">http://www.trendmicro.com/ftp/documentation/readme/spnt_558_win_en_securitypatch1_readme.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0670" xml:lang="en">ADV-2007-0670</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32594" xml:lang="en">serverprotect-eng50-bo(32594)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32601" xml:lang="en">serverprotect-stcommon-bo(32601)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple stack-based buffer overflows in Trend Micro ServerProtect for Windows and EMC 5.58, and for Network Appliance Filer 5.61 and 5.62, allow remote attackers to execute arbitrary code via crafted RPC requests to TmRpcSrv.dll that trigger overflows when calling the (1) CMON_NetTestConnection, (2) CMON_ActiveUpdate, and (3) CMON_ActiveRollback functions in (a) StCommon.dll, and (4) ENG_SetRealTimeScanConfigInfo and (5) ENG_SendEMail functions in (b) eng50.dll.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1071">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.8"/>
        <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x_server:10.4.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:apple:mac_os_x:10.4.8</vuln:product>
      <vuln:product>cpe:/o:apple:mac_os_x_server:10.4.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1071</vuln:cve-id>
    <vuln:published-datetime>2007-02-22T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:51:14.987-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305214" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" xml:lang="en">APPLE-SA-2007-03-13</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://security-protocols.com/sp-x39-advisory.php" xml:lang="en">http://security-protocols.com/sp-x39-advisory.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/559444" xml:lang="en">VU#559444</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22630" xml:lang="en">22630</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017758" xml:lang="en">1017758</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" xml:lang="en">TA07-072A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0930" xml:lang="en">ADV-2007-0930</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in the gifGetBandProc function in ImageIO in Apple Mac OS X 10.4.8 allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a crafted GIF image that triggers the overflow during decompression.  NOTE: this is a different issue than CVE-2006-3502 and CVE-2006-3503.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1072">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:cisco:unified_ip_phone_firmware_7906g:8.0%284%29:sr1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/h:cisco:unified_ip_phone_7906g:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:cisco:unified_ip_phone_firmware_7911g:8.0%284%29:sr1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/h:cisco:unified_ip_phone_7911g:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:cisco:unified_ip_phone_firmware_7941g:8.0%284%29:sr1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/h:cisco:unified_ip_phone_7941g:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:cisco:unified_ip_phone_firmware_7961g:8.0%284%29:sr1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/h:cisco:unified_ip_phone_7961g:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:cisco:unified_ip_phone_firmware_7970g:8.0%284%29:sr1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/h:cisco:unified_ip_phone_7970g:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:cisco:unified_ip_phone_firmware_7971g:8.0%284%29:sr1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/h:cisco:unified_ip_phone_7971g:-"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:cisco:unified_ip_phone_firmware_7906g:8.0%284%29:sr1</vuln:product>
      <vuln:product>cpe:/o:cisco:unified_ip_phone_firmware_7911g:8.0%284%29:sr1</vuln:product>
      <vuln:product>cpe:/o:cisco:unified_ip_phone_firmware_7941g:8.0%284%29:sr1</vuln:product>
      <vuln:product>cpe:/o:cisco:unified_ip_phone_firmware_7961g:8.0%284%29:sr1</vuln:product>
      <vuln:product>cpe:/o:cisco:unified_ip_phone_firmware_7970g:8.0%284%29:sr1</vuln:product>
      <vuln:product>cpe:/o:cisco:unified_ip_phone_firmware_7971g:8.0%284%29:sr1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1072</vuln:cve-id>
    <vuln:published-datetime>2007-02-22T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-05-23T12:16:04.877-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2019-05-22T11:10:42.273-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-air-20070221-phone.shtml" xml:lang="en">20070221 Identifying and Mitigating Exploitation of Cisco Unified IP Conference Station and IP Phone Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20070221-phone.shtml" xml:lang="en">20070221 Cisco Unified IP Conference Station and IP Phone Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22647" xml:lang="en">22647</vuln:reference>
    </vuln:references>
    <vuln:summary>The command line interface (CLI) in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G, with firmware 8.0(4)SR1 and earlier allows local users to obtain privileges or cause a denial of service via unspecified vectors.  NOTE: this issue can be leveraged remotely via CVE-2007-1063.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1073">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mcrefer:mcrefer"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mcrefer:mcrefer</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1073</vuln:cve-id>
    <vuln:published-datetime>2007-02-22T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:34.517-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2283" xml:lang="en">2283</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/459796/100/200/threaded" xml:lang="en">20070211 Re: mcRefer SQL injection</vuln:reference>
    </vuln:references>
    <vuln:summary>Static code injection vulnerability in install.php in mcRefer allows remote attackers to execute arbitrary PHP code via the bgcolor parameter, which is inserted into mcrconf.inc.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1074">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:dji:newsbin_pro:4.x"/>
        <cpe-lang:fact-ref name="cpe:/a:dji:newsbin_pro:5.33"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:dji:newsbin_pro:4.x</vuln:product>
      <vuln:product>cpe:/a:dji:newsbin_pro:5.33</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1074</vuln:cve-id>
    <vuln:published-datetime>2007-02-22T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:44.847-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22652" xml:lang="en">22652</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0694" xml:lang="en">ADV-2007-0694</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32598" xml:lang="en">newsbinpro-nbi-bo(32598)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32608" xml:lang="en">newsbinpro-nzb-bo(32608)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3349" xml:lang="en">3349</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in NewsBin Pro 5.33 and NewsBin Pro 4.x allow user-assisted remote attackers to execute arbitrary code via a long (1) DataPath or (2) DownloadPath attributed in a (a) NBI file, or (3) a long group field in a (b) NZB file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1075">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:turbosoft:turboftp:5.3.0:build_572"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:turbosoft:turboftp:5.3.0:build_572</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1075</vuln:cve-id>
    <vuln:published-datetime>2007-02-22T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:44.923-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22634" xml:lang="en">22634</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3341" xml:lang="en">3341</vuln:reference>
    </vuln:references>
    <vuln:summary>TurboFTP 5.30 Build 572 allows remote servers to cause a denial of service (CPU consumption) via a response with a large number of newline characters.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1076">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phptraffica:phptraffica:1.4.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phptraffica:phptraffica:1.4.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1076</vuln:cve-id>
    <vuln:published-datetime>2007-02-22T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:36.797-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://attrition.org/pipermail/vim/2007-February/001377.html" xml:lang="en">20070222 [true] phpTrafficA-1.4.1 Local File Inclusion</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://soft.zoneo.net/phpTrafficA/news.php" xml:lang="en">http://soft.zoneo.net/phpTrafficA/news.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.bugtraq.ir/articles/file-inclusion/phpTrafficA-1.4.1-Local-File-Inclusion/1" xml:lang="en">http://www.bugtraq.ir/articles/file-inclusion/phpTrafficA-1.4.1-Local-File-Inclusion/1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22655" xml:lang="en">22655</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0709" xml:lang="en">ADV-2007-0709</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32628" xml:lang="en">phptraffica-plotstat-banref-file-include(32628)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple directory traversal vulnerabilities in phpTrafficA 1.4.1, and possibly earlier, allow remote attackers to include arbitrary local files via a .. (dot dot) in the (1) file parameter to plotStat.php and the (2) lang parameter to banref.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1077">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:design4online:userpages2:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:design4online:userpages2:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1077</vuln:cve-id>
    <vuln:published-datetime>2007-02-22T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:43:05.453-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22636" xml:lang="en">22636</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in page.asp in Design4Online UserPages2 2.0 allows remote attackers to execute arbitrary SQL commands via the art_id parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1078">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:flashgamescript:flashgamescript:1.5.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:flashgamescript:flashgamescript:1.5.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1078</vuln:cve-id>
    <vuln:published-datetime>2007-02-22T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:34.657-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460951/100/0/threaded" xml:lang="en">20070221 FlashGameScript v1.5.4 Remote File Inclusion Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22646" xml:lang="en">22646</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0707" xml:lang="en">ADV-2007-0707</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32635" xml:lang="en">flashgamescript-index-file-include(32635)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3360" xml:lang="en">3360</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in index.php in FlashGameScript 1.5.4 allows remote attackers to execute arbitrary PHP code via a URL in the func parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1079">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:rhinosoft:ftp_voyager:14.0.0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rhinosoft:ftp_voyager:14.0.0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1079</vuln:cve-id>
    <vuln:published-datetime>2007-02-22T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:45.033-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22637" xml:lang="en">22637</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32593" xml:lang="en">ftpvoyager-cwd-dos(32593)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3343" xml:lang="en">3343</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in Rhino Software, Inc. FTP Voyager 14.0.0.3 and earlier allows remote servers to cause a denial of service (crash) via a long response to a CWD command, which triggers the overflow when the user aborts the command.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1080">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:turbosoft:turboftp:5.3.0:build_572"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:turbosoft:turboftp:5.3.0:build_572</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1080</vuln:cve-id>
    <vuln:published-datetime>2007-02-22T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:45.097-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22634" xml:lang="en">22634</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32604" xml:lang="en">turboftp-list-dos(32604)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32605" xml:lang="en">turboftp-cwd-dos(32605)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3341" xml:lang="en">3341</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple heap-based buffer overflows in TurboFTP 5.30 Build 572 allow remote servers to cause a denial of service via (1) long filename in a response to a LIST command, and (2) a long response to a CWD command.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1081">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:typo3:typo3:4.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:typo3:typo3:4.1:beta"/>
        <cpe-lang:fact-ref name="cpe:/a:typo3:typo3:4.1:rc1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:typo3:typo3:4.0.4</vuln:product>
      <vuln:product>cpe:/a:typo3:typo3:4.1:beta</vuln:product>
      <vuln:product>cpe:/a:typo3:typo3:4.1:rc1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1081</vuln:cve-id>
    <vuln:published-datetime>2007-02-22T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:37.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://typo3.org/teams/security/security-bulletins/typo3-20070221-1" xml:lang="en">http://typo3.org/teams/security/security-bulletins/typo3-20070221-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22668" xml:lang="en">22668</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0697" xml:lang="en">ADV-2007-0697</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32630" xml:lang="en">typo3-t3libformmail-header-injection(32630)</vuln:reference>
    </vuln:references>
    <vuln:summary>The start function in class.t3lib_formmail.php in TYPO3 before 4.0.5, 4.1beta, and 4.1RC1 allows attackers to inject arbitrary email headers via unknown vectors.  NOTE: some details were obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1082">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ftpx:ftp_explorer:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ftpx:ftp_explorer:1.0.1.47"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ftpx:ftp_explorer:1.0.1</vuln:product>
      <vuln:product>cpe:/a:ftpx:ftp_explorer:1.0.1.47</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1082</vuln:cve-id>
    <vuln:published-datetime>2007-02-22T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:45.173-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-March/001470.html" xml:lang="en">20070324 Vendor ACK for FTPx DoS (CVE-2007-1082)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22640" xml:lang="en">22640</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32606" xml:lang="en">ftpexplorer-pwd-dos(32606)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3347" xml:lang="en">3347</vuln:reference>
    </vuln:references>
    <vuln:summary>FTP Explorer 1.0.1 Build 047, and other versions before 1.0.1.52, allows remote servers to cause a denial of service (CPU consumption) via a long response to a PWD command.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1083">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:verisign:mpki:4.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:verisign:mpki:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:verisign:mpki:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:verisign:mpki:6.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:verisign:mpki:7.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:verisign:mpki:4.6.1</vuln:product>
      <vuln:product>cpe:/a:verisign:mpki:5.0</vuln:product>
      <vuln:product>cpe:/a:verisign:mpki:6.0</vuln:product>
      <vuln:product>cpe:/a:verisign:mpki:6.1.3</vuln:product>
      <vuln:product>cpe:/a:verisign:mpki:7.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1083</vuln:cve-id>
    <vuln:published-datetime>2007-02-22T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:37.127-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://attrition.org/pipermail/vim/2007-February/001384.html" xml:lang="en">20070222 Verisign ConfigChk ActiveX Overflow(s)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://attrition.org/pipermail/vim/2007-February/001385.html" xml:lang="en">20070223 Verisign ConfigChk ActiveX Overflow(s)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://jvn.jp/cert/JVNVU%23308087/index.html" xml:lang="en">http://jvn.jp/cert/JVNVU%23308087/index.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=479" xml:lang="en">20070222 VeriSign ConfigChk ActiveX Control Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.jpcert.or.jp/at/2007/at070006.txt" xml:lang="en">http://www.jpcert.or.jp/at/2007/at070006.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/308087" xml:lang="en">VU#308087</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22671" xml:lang="en">22671</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22676" xml:lang="en">22676</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017692" xml:lang="en">1017692</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017693" xml:lang="en">1017693</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017694" xml:lang="en">1017694</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0702" xml:lang="en">ADV-2007-0702</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://download.verisign.co.jp/support/announce/20070216.html" xml:lang="en">https://download.verisign.co.jp/support/announce/20070216.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32639" xml:lang="en">verisign-configchk-bo(32639)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the Configuration Checker (ConfigChk) ActiveX control in VSCnfChk.dll 2.0.0.2 for Verisign Managed PKI Service, Secure Messaging for Microsoft Exchange, and Go Secure! allows remote attackers to execute arbitrary code via long arguments to the VerCompare method.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1084">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:firefox:0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.10.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1084</vuln:cve-id>
    <vuln:published-datetime>2007-02-22T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:35.047-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-16"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0490.html" xml:lang="en">20070221 Firefox bookmark cross-domain surfing vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://lcamtuf.coredump.cx/ffbook" xml:lang="en">http://lcamtuf.coredump.cx/ffbook</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://lcamtuf.coredump.cx/ffbook/" xml:lang="en">http://lcamtuf.coredump.cx/ffbook/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2304" xml:lang="en">2304</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.heise-security.co.uk/news/85728" xml:lang="en">http://www.heise-security.co.uk/news/85728</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460885/100/0/threaded" xml:lang="en">20070221 Firefox bookmark cross-domain surfing vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460890/100/0/threaded" xml:lang="en">20070221 Re: [Full-disclosure] Firefox bookmark cross-domain surfing vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460896/100/0/threaded" xml:lang="en">20070221 Re: [Full-disclosure] Firefox bookmark cross-domain surfing vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461021/100/0/threaded" xml:lang="en">20070223 Re: [Full-disclosure] Firefox bookmark cross-domain surfingvulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22666" xml:lang="en">22666</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=371179" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=371179</vuln:reference>
    </vuln:references>
    <vuln:summary>Mozilla Firefox 2.0.0.1 and earlier does not prompt users before saving bookmarklets, which allows remote attackers to bypass the same-domain policy by tricking a user into saving a bookmarklet with a data: scheme, which is executed in the context of the last visited web page.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1085">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:google:desktop"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:google:desktop</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1085</vuln:cve-id>
    <vuln:published-datetime>2007-02-22T22:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:35.767-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2301" xml:lang="en">2301</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/615857" xml:lang="en">VU#615857</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460735/100/0/threaded" xml:lang="en">20070221 Overtaking Google Desktop</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460928/100/0/threaded" xml:lang="en">20070222 RE: Overtaking Google Desktop</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22650" xml:lang="en">22650</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017686" xml:lang="en">1017686</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.watchfire.com/resources/Overtaking-Google-Desktop.pdf" xml:lang="en">http://www.watchfire.com/resources/Overtaking-Google-Desktop.pdf</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Google Desktop allows remote attackers to bypass protection schemes and inject arbitrary web script or HTML, and possibly gain full access to the system, by using an XSS vulnerability in google.com to extract the signature for the internal web server, then calling the "under" parameter in Advanced Search with the proper signature.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1086">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux"/>
          <cpe-lang:fact-ref name="cpe:/o:ibm:aix"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.0"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.1"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.2"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.3"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.4"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.5"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.6"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.7"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.1"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.2"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.3"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.4"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp"/>
          <cpe-lang:fact-ref name="cpe:/o:sun:solaris"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:8.0::linux"/>
          <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:8.1::aix"/>
          <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:8.1.4"/>
          <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:8.1.5"/>
          <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:8.1.6"/>
          <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:8.1.6c"/>
          <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:8.1.7"/>
          <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:8.1.7b"/>
          <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:8.1.8"/>
          <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:8.1.8a"/>
          <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:8.1.9"/>
          <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:8.1.9a"/>
          <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:8.10"/>
          <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:8.12"/>
          <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1::hp_ux"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:db2_universal_database:8.0::linux</vuln:product>
      <vuln:product>cpe:/a:ibm:db2_universal_database:8.1::aix</vuln:product>
      <vuln:product>cpe:/a:ibm:db2_universal_database:8.1.4</vuln:product>
      <vuln:product>cpe:/a:ibm:db2_universal_database:8.1.5</vuln:product>
      <vuln:product>cpe:/a:ibm:db2_universal_database:8.1.6</vuln:product>
      <vuln:product>cpe:/a:ibm:db2_universal_database:8.1.6c</vuln:product>
      <vuln:product>cpe:/a:ibm:db2_universal_database:8.1.7</vuln:product>
      <vuln:product>cpe:/a:ibm:db2_universal_database:8.1.7b</vuln:product>
      <vuln:product>cpe:/a:ibm:db2_universal_database:8.1.8</vuln:product>
      <vuln:product>cpe:/a:ibm:db2_universal_database:8.1.8a</vuln:product>
      <vuln:product>cpe:/a:ibm:db2_universal_database:8.1.9</vuln:product>
      <vuln:product>cpe:/a:ibm:db2_universal_database:8.1.9a</vuln:product>
      <vuln:product>cpe:/a:ibm:db2_universal_database:8.10</vuln:product>
      <vuln:product>cpe:/a:ibm:db2_universal_database:8.12</vuln:product>
      <vuln:product>cpe:/a:ibm:db2_universal_database:9.1::hp_ux</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1086</vuln:cve-id>
    <vuln:published-datetime>2007-02-23T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:10.013-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=481" xml:lang="en">20070222 IBM DB2 Universal Database Multiple Privilege Escalation Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-August/001765.html" xml:lang="en">20070818 Recent DB2 Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22677" xml:lang="en">22677</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?uid=swg21255747" xml:lang="en">IY94833</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32650" xml:lang="en">db2-setuid-privilege-escalation(32650)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified binaries in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allow local users to create or modify arbitrary files via unspecified environment variables related to "unsafe file access."</vuln:summary>
  </entry>
  <entry id="CVE-2007-1087">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.0:fp13"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.0:fp14"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.0:fp8"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.0:fp9"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.1:fp13"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.1:fp14"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.1.6c"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.1.7b"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.1.8a"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.1.9a"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:9.1:fp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:db2:8.0</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:8.0:fp13</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:8.0:fp14</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:8.0:fp8</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:8.0:fp9</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:8.1</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:8.1:fp13</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:8.1:fp14</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:8.1.4</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:8.1.5</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:8.1.6</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:8.1.6c</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:8.1.7</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:8.1.7b</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:8.1.8</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:8.1.8a</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:8.1.9</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:8.1.9a</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:9.1</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:9.1:fp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1087</vuln:cve-id>
    <vuln:published-datetime>2007-02-23T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-05-23T13:02:07.083-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2019-05-23T10:48:54.850-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=481" xml:lang="en">20070222 IBM DB2 Universal Database Multiple Privilege Escalation Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-August/001765.html" xml:lang="en">20070818 Recent DB2 Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22677" xml:lang="en">22677</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?uid=swg21255747" xml:lang="en">IY94833</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32651" xml:lang="en">db2-bss-bo(32651)</vuln:reference>
    </vuln:references>
    <vuln:summary>IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 does not properly terminate certain input strings, which allows local users to execute arbitrary code via unspecified environment variables that trigger a heap-based buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1088">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.0:fp13"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.0:fp14"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.0:fp8"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.0:fp9"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.1:fp13"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.1:fp14"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.1.6c"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.1.7"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.1.7b"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.1.8a"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.1.9"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.1.9a"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ibm:db2:9.1:fp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:db2:8.0</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:8.0:fp13</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:8.0:fp14</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:8.0:fp8</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:8.0:fp9</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:8.1</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:8.1:fp13</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:8.1:fp14</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:8.1.4</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:8.1.5</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:8.1.6</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:8.1.6c</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:8.1.7</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:8.1.7b</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:8.1.8</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:8.1.8a</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:8.1.9</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:8.1.9a</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:9.1</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:9.1:fp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1088</vuln:cve-id>
    <vuln:published-datetime>2007-02-23T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-05-23T13:06:48.103-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2019-05-23T10:48:05.413-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=481" xml:lang="en">20070222 IBM DB2 Universal Database Multiple Privilege Escalation Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-August/001765.html" xml:lang="en">20070818 Recent DB2 Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22677" xml:lang="en">22677</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?uid=swg21255747" xml:lang="en">IY94833</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32652" xml:lang="en">db2-variable-bo(32652)</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allows local users to execute arbitrary code via a long string in unspecified environment variables.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1089">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.0"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.1"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.2"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.3"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.4"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.5"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.6"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.7"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.1"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.2"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.3"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.4"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20"/>
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.1"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1::aix"/>
          <cpe-lang:fact-ref name="cpe:/a:ibm:db2_universal_database:9.1:ga"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:db2_universal_database:9.1::aix</vuln:product>
      <vuln:product>cpe:/a:ibm:db2_universal_database:9.1:ga</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1089</vuln:cve-id>
    <vuln:published-datetime>2007-02-23T17:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:10.013-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-August/001765.html" xml:lang="en">20070818 Recent DB2 Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0721" xml:lang="en">ADV-2007-0721</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?uid=swg1JR25941" xml:lang="en">JR25941</vuln:reference>
    </vuln:references>
    <vuln:summary>IBM DB2 Universal Database (UDB) 9.1 GA through 9.1 FP1 allows local users with table SELECT privileges to perform unauthorized UPDATE and DELETE SQL commands via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1090">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_explorer"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:windows_explorer</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1090</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:36.140-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://securityvulns.com/news/Microsoft/Windows/Explorer/DoS.html" xml:lang="en">http://securityvulns.com/news/Microsoft/Windows/Explorer/DoS.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://securityvulns.com/Qdocument170.html" xml:lang="en">http://securityvulns.com/Qdocument170.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461373/100/0/threaded" xml:lang="en">20070225 Few unreported vulnerabilities by SehaTo</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22715" xml:lang="en">22715</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Windows Explorer on Windows XP and 2003 allows remote user-assisted attackers to cause a denial of service (crash) via a malformed WMF file, which triggers the crash when the user browses the folder.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1091">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7.0::vista"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:7.0::vista</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1091</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T06:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:36.390-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2162" name="oval:org.mitre.oval:def:2162"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://lcamtuf.coredump.cx/ietrap" xml:lang="en">http://lcamtuf.coredump.cx/ietrap</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052630.html" xml:lang="en">20070223 MSIE7 browser entrapment vulnerability (probably Firefox, too)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2291" xml:lang="en">2291</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1018788" xml:lang="en">1018788</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461023/100/0/threaded" xml:lang="en">20070223 MSIE7 browser entrapment vulnerability (probably Firefox, too)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461027/100/0/threaded" xml:lang="en">20070223 Secunia Research: Internet Explorer 7 "onunload" Event SpoofingVulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/482366/100/0/threaded" xml:lang="en">HPSBST02280</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22680" xml:lang="en">22680</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-282A.html" xml:lang="en">TA07-282A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0713" xml:lang="en">ADV-2007-0713</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-057" xml:lang="en">MS07-057</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32647" xml:lang="en">ie-mozilla-onunload-dos(32647)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32649" xml:lang="en">ie-mozilla-onunload-url-spoofing(32649)</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Internet Explorer 7 allows remote attackers to prevent users from leaving a site, spoof the address bar, and conduct phishing and other attacks via onUnload Javascript handlers.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1092">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1092</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:37.437-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11158" name="oval:org.mitre.oval:def:11158"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc" xml:lang="en">20070202-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" xml:lang="en">20070301-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0525.html" xml:lang="en">20070222 Firefox onUnload + document.write() memory corruption vulnerability (MSIE7 null ptr)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" xml:lang="en">HPSBUX02153</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html" xml:lang="en">SUSE-SA:2007:019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2302" xml:lang="en">2302</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131" xml:lang="en">SSA:2007-066-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/393921" xml:lang="en">VU#393921</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:050" xml:lang="en">MDKSA-2007:050</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2007/mfsa2007-08.html" xml:lang="en">http://www.mozilla.org/security/announce/2007/mfsa2007-08.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html" xml:lang="en">SUSE-SA:2007:022</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0078.html" xml:lang="en">RHSA-2007:0078</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461024/100/0/threaded" xml:lang="en">20070223 Firefox onUnload + document.write() memory corruption vulnerability (MSIE7 null ptr)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22679" xml:lang="en">22679</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017701" xml:lang="en">1017701</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-428-1" xml:lang="en">USN-428-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=371321" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=371321</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32647" xml:lang="en">ie-mozilla-onunload-dos(32647)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32648" xml:lang="en">mozilla-onunload-code-execution(32648)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1103" xml:lang="en">https://issues.rpath.com/browse/RPL-1103</vuln:reference>
    </vuln:references>
    <vuln:summary>Mozilla Firefox 1.5.0.9 and 2.0.0.1, and SeaMonkey before 1.0.8 allow remote attackers to execute arbitrary code via JavaScript onUnload handlers that modify the structure of a document, wich triggers memory corruption due to the lack of a finalize hook on DOM window objects.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1093">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:hitachi:hi_ux_we2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:hitachi:cm2-network_node_manager:05_00::enterprise"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:all_windows:abstract_cpe"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:hitachi:cm2-network_node_manager:05_00::unlimited"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:hitachi:cm2-network_node_manager_250:05_00"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:cm2-network_node_manager_250:05_00_c"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:all_windows:abstract_cpe"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:hitachi:cm2-network_node_manager_250:05_00"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:cm2-network_node_manager_250:05_00_a"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:hitachi:hi_ux_we2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:hitachi:cm2-network_node_manager_250:05_00"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager:05_20::enterprise"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager:05_20_e::enterprise"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager:06_00::enterprise"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager:06_50_a::enterprise"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager:06_51::enterprise"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager:06_71_c::enterprise"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:all_windows:abstract_cpe"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager:05_20::enterprise"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager:05_20_e::enterprise"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager:05_20_f::enterprise"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager:06_00::enterprise"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager:06_50_a::enterprise"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager:06_51::enterprise"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager:06_71_c::enterprise"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager:06_71_d::enterprise"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:sun:solaris"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager:05_20::enterprise"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager:05_20_e::enterprise"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager:06_00::enterprise"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager:06_50_a::enterprise"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager:06_51::enterprise"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager:06_71_c::enterprise"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager_250:05_20"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager_250:05_20_e"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager_250:06_00"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager_250:06_50_a"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager_250:06_51"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager_250:06_71_c"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:all_windows:abstract_cpe"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager_250:05_20"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager_250:05_20_e"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager_250:05_20_f"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager_250:06_00"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager_250:06_50_a"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager_250:06_51"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager_250:06_71_c"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager_250:06_71_d"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:sun:solaris"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager_250:05_20"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager_250:05_20_e"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager_250:06_00"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager_250:06_50_a"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager_250:06_51"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager_250:06_71_c"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager:07_00"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager:07_10_04"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:all_windows:abstract_cpe"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager:07_00"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager:07_10_04"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:sun:solaris"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager:07_00"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager:07_10_04"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/h:hp:pa-risc"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager_starter:08_00::enterprise"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager_starter:08_00_01::enterprise"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:all_windows:abstract_cpe"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager_starter:08_00::enterprise"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager_starter:08_00_01::enterprise"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:hp:ipfilter"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager_starter:08_00::enterprise"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager_starter:08_00_01::enterprise"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/h:hp:pa-risc"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager_starter_250:08_00"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager_starter_250:08_00_01"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:sun:solaris"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager_starter:08_00::enterprise"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager_starter:08_00_01::enterprise"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:all_windows:abstract_cpe"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager_starter_250:08_00"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager_starter_250:08_00_01"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:hp:ipfilter"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager_starter_250:08_00"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager_starter_250:08_00_01"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:hitachi:cm2-network_node_manager:05_00::enterprise"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:cm2-network_node_manager:05_00_c::enterprise"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:sun:solaris"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager_starter_250:08_00"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:jp1-cm2-network_node_manager_starter_250:08_00_01"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hitachi:cm2-network_node_manager:05_00::enterprise</vuln:product>
      <vuln:product>cpe:/a:hitachi:cm2-network_node_manager:05_00::unlimited</vuln:product>
      <vuln:product>cpe:/a:hitachi:cm2-network_node_manager:05_00_c::enterprise</vuln:product>
      <vuln:product>cpe:/a:hitachi:cm2-network_node_manager_250:05_00</vuln:product>
      <vuln:product>cpe:/a:hitachi:cm2-network_node_manager_250:05_00_a</vuln:product>
      <vuln:product>cpe:/a:hitachi:cm2-network_node_manager_250:05_00_c</vuln:product>
      <vuln:product>cpe:/a:hitachi:jp1-cm2-network_node_manager:05_20::enterprise</vuln:product>
      <vuln:product>cpe:/a:hitachi:jp1-cm2-network_node_manager:05_20_e::enterprise</vuln:product>
      <vuln:product>cpe:/a:hitachi:jp1-cm2-network_node_manager:05_20_f::enterprise</vuln:product>
      <vuln:product>cpe:/a:hitachi:jp1-cm2-network_node_manager:06_00::enterprise</vuln:product>
      <vuln:product>cpe:/a:hitachi:jp1-cm2-network_node_manager:06_50_a::enterprise</vuln:product>
      <vuln:product>cpe:/a:hitachi:jp1-cm2-network_node_manager:06_51::enterprise</vuln:product>
      <vuln:product>cpe:/a:hitachi:jp1-cm2-network_node_manager:06_71_c::enterprise</vuln:product>
      <vuln:product>cpe:/a:hitachi:jp1-cm2-network_node_manager:06_71_d::enterprise</vuln:product>
      <vuln:product>cpe:/a:hitachi:jp1-cm2-network_node_manager:07_00</vuln:product>
      <vuln:product>cpe:/a:hitachi:jp1-cm2-network_node_manager:07_10_04</vuln:product>
      <vuln:product>cpe:/a:hitachi:jp1-cm2-network_node_manager_250:05_20</vuln:product>
      <vuln:product>cpe:/a:hitachi:jp1-cm2-network_node_manager_250:05_20_e</vuln:product>
      <vuln:product>cpe:/a:hitachi:jp1-cm2-network_node_manager_250:05_20_f</vuln:product>
      <vuln:product>cpe:/a:hitachi:jp1-cm2-network_node_manager_250:06_00</vuln:product>
      <vuln:product>cpe:/a:hitachi:jp1-cm2-network_node_manager_250:06_50_a</vuln:product>
      <vuln:product>cpe:/a:hitachi:jp1-cm2-network_node_manager_250:06_51</vuln:product>
      <vuln:product>cpe:/a:hitachi:jp1-cm2-network_node_manager_250:06_71_c</vuln:product>
      <vuln:product>cpe:/a:hitachi:jp1-cm2-network_node_manager_250:06_71_d</vuln:product>
      <vuln:product>cpe:/a:hitachi:jp1-cm2-network_node_manager_starter:08_00::enterprise</vuln:product>
      <vuln:product>cpe:/a:hitachi:jp1-cm2-network_node_manager_starter:08_00_01::enterprise</vuln:product>
      <vuln:product>cpe:/a:hitachi:jp1-cm2-network_node_manager_starter_250:08_00</vuln:product>
      <vuln:product>cpe:/a:hitachi:jp1-cm2-network_node_manager_starter_250:08_00_01</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1093</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:37.640-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.hitachi-support.com/security_e/vuls_e/HS07-002_e/index-e.html" xml:lang="en">http://www.hitachi-support.com/security_e/vuls_e/HS07-002_e/index-e.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0739" xml:lang="en">ADV-2007-0739</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32682" xml:lang="en">nnm-unspecified-code-execution(32682)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32683" xml:lang="en">nnm-unspecified-dos(32683)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple unspecified vulnerabilities in JP1/Cm2/Network Node Manager (NNM) before 07-10-05, and before 08-00-02 in the 08-x series, allow remote attackers to execute arbitrary code, cause a denial of service, or trigger invalid Web utility behavior.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1094">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:6.0:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7.0::vista"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:6.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:6.0:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:7.0::vista</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1094</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:39.250-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2302" xml:lang="en">2302</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461024/100/0/threaded" xml:lang="en">20070223 Firefox onUnload + document.write() memory corruption vulnerability (MSIE7 null ptr)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22678" xml:lang="en">22678</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32647" xml:lang="en">ie-mozilla-onunload-dos(32647)</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Internet Explorer 7 allows remote attackers to cause a denial of service (NULL dereference and application crash) via JavaScript onUnload handlers that modify the structure of a document.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1095">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9:rc"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:0.10.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0:preview_release"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:firefox:0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.6.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.7.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9:rc</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.9.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:0.10.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0:preview_release</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.4.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5:beta2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.10</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.11</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.0.12</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.5.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:1.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1095</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:39.577-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11665" name="oval:org.mitre.oval:def:11665"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" xml:lang="en">HPSBUX02153</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://lcamtuf.coredump.cx/ietrap/ff/" xml:lang="en">http://lcamtuf.coredump.cx/ietrap/ff/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052630.html" xml:lang="en">20070223 MSIE7 browser entrapment vulnerability (probably Firefox, too)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2310" xml:lang="en">2310</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1018837" xml:lang="en">1018837</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201516-1" xml:lang="en">201516</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.novell.com/techcenter/psdb/60eb95b75c76f9fbfcc9a89f99cd8f79.html" xml:lang="en">http://support.novell.com/techcenter/psdb/60eb95b75c76f9fbfcc9a89f99cd8f79.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1392" xml:lang="en">DSA-1392</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1396" xml:lang="en">DSA-1396</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1401" xml:lang="en">DSA-1401</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200711-14.xml" xml:lang="en">GLSA-200711-14</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/en/security/advisories?name=MDKSA-2007:202" xml:lang="en">MDKSA-2007:202</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2007/mfsa2007-30.html" xml:lang="en">http://www.mozilla.org/security/announce/2007/mfsa2007-30.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_57_mozilla.html" xml:lang="en">SUSE-SA:2007:057</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0979.html" xml:lang="en">RHSA-2007:0979</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0980.html" xml:lang="en">RHSA-2007:0980</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0981.html" xml:lang="en">RHSA-2007:0981</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461007/100/0/threaded" xml:lang="en">20070223 Firefox: onUnload tailgating (MSIE7 entrapment bug variant)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461023/100/0/threaded" xml:lang="en">20070223 MSIE7 browser entrapment vulnerability (probably Firefox, too)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/482876/100/200/threaded" xml:lang="en">20071026 rPSA-2007-0225-1 firefox</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/482925/100/0/threaded" xml:lang="en">20071029 FLEA-2007-0062-1 firefox</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/482932/100/200/threaded" xml:lang="en">20071029 rPSA-2007-0225-2 firefox thunderbird</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22688" xml:lang="en">22688</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-536-1" xml:lang="en">USN-536-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/3544" xml:lang="en">ADV-2007-3544</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/3587" xml:lang="en">ADV-2007-3587</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0083" xml:lang="en">ADV-2008-0083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=371360" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=371360</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32647" xml:lang="en">ie-mozilla-onunload-dos(32647)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32649" xml:lang="en">ie-mozilla-onunload-url-spoofing(32649)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1858" xml:lang="en">https://issues.rpath.com/browse/RPL-1858</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="https://usn.ubuntu.com/535-1/" xml:lang="en">USN-535-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00498.html" xml:lang="en">FEDORA-2007-3431</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00285.html" xml:lang="en">FEDORA-2007-2601</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00355.html" xml:lang="en">FEDORA-2007-2664</vuln:reference>
    </vuln:references>
    <vuln:summary>Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 do not properly implement JavaScript onUnload handlers, which allows remote attackers to run certain JavaScript code and access the location DOM hierarchy in the context of the next web site that is visited by a client.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1096">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:virtuemart:virtuemart:1.0.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:virtuemart:virtuemart:1.0.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1096</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-08-13T17:47:28.837-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://virtuemart.svn.sourceforge.net/viewvc/*checkout*/virtuemart/trunk/virtuemart/CHANGELOG.php?revision=692" xml:lang="en">http://virtuemart.svn.sourceforge.net/viewvc/*checkout*/virtuemart/trunk/virtuemart/CHANGELOG.php?revision=692</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0817" xml:lang="en">ADV-2007-0817</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in ps_cart.php in VirtueMart before 20070116 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: this issue might overlap CVE-2007-0376.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1097">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:wiclear:wiclear:0.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wiclear:wiclear:0.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1097</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:37.890-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://wiclear.free.fr/?Download" xml:lang="en">http://wiclear.free.fr/?Download</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0792" xml:lang="en">ADV-2007-0792</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32757" xml:lang="en">wiclear-onattachfiles-file-upload(32757)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unrestricted file upload vulnerability in the onAttachFiles function in the upload tool (inc/lib/attachment.lib.php) in Wiclear before 0.11.1 allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors related to filename validation.  NOTE: some details were obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1098">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:scrymud:scrymud:2.1.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:scrymud:scrymud:2.1.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1098</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:43:14.703-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://scrymud.net/downloads/Changelog-2.1.10-2.1.11.txt" xml:lang="en">http://scrymud.net/downloads/Changelog-2.1.10-2.1.11.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.wanfear.com/pipermail/scrymud/2007q1/001157.html" xml:lang="en">[ScryMUD] 20070223 ScryMUD 2.1.11 (stable) has been released.</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple unspecified vulnerabilities in ScryMUD before 2.1.11 have unknown impact and attack vectors, possibly related to denial of service caused by a search that begins with a .* sequence.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1099">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:dropbear_ssh_project:dropbear_ssh:0.28"/>
        <cpe-lang:fact-ref name="cpe:/a:dropbear_ssh_project:dropbear_ssh:0.29"/>
        <cpe-lang:fact-ref name="cpe:/a:dropbear_ssh_project:dropbear_ssh:0.30"/>
        <cpe-lang:fact-ref name="cpe:/a:dropbear_ssh_project:dropbear_ssh:0.31"/>
        <cpe-lang:fact-ref name="cpe:/a:dropbear_ssh_project:dropbear_ssh:0.32"/>
        <cpe-lang:fact-ref name="cpe:/a:dropbear_ssh_project:dropbear_ssh:0.33"/>
        <cpe-lang:fact-ref name="cpe:/a:dropbear_ssh_project:dropbear_ssh:0.34"/>
        <cpe-lang:fact-ref name="cpe:/a:dropbear_ssh_project:dropbear_ssh:0.35"/>
        <cpe-lang:fact-ref name="cpe:/a:dropbear_ssh_project:dropbear_ssh:0.36"/>
        <cpe-lang:fact-ref name="cpe:/a:dropbear_ssh_project:dropbear_ssh:0.37"/>
        <cpe-lang:fact-ref name="cpe:/a:dropbear_ssh_project:dropbear_ssh:0.38"/>
        <cpe-lang:fact-ref name="cpe:/a:dropbear_ssh_project:dropbear_ssh:0.39"/>
        <cpe-lang:fact-ref name="cpe:/a:dropbear_ssh_project:dropbear_ssh:0.40"/>
        <cpe-lang:fact-ref name="cpe:/a:dropbear_ssh_project:dropbear_ssh:0.41"/>
        <cpe-lang:fact-ref name="cpe:/a:dropbear_ssh_project:dropbear_ssh:0.42"/>
        <cpe-lang:fact-ref name="cpe:/a:dropbear_ssh_project:dropbear_ssh:0.43"/>
        <cpe-lang:fact-ref name="cpe:/a:dropbear_ssh_project:dropbear_ssh:0.44"/>
        <cpe-lang:fact-ref name="cpe:/a:dropbear_ssh_project:dropbear_ssh:0.44:test1"/>
        <cpe-lang:fact-ref name="cpe:/a:dropbear_ssh_project:dropbear_ssh:0.44:test2"/>
        <cpe-lang:fact-ref name="cpe:/a:dropbear_ssh_project:dropbear_ssh:0.44:test3"/>
        <cpe-lang:fact-ref name="cpe:/a:dropbear_ssh_project:dropbear_ssh:0.44:test4"/>
        <cpe-lang:fact-ref name="cpe:/a:dropbear_ssh_project:dropbear_ssh:0.45"/>
        <cpe-lang:fact-ref name="cpe:/a:dropbear_ssh_project:dropbear_ssh:0.46"/>
        <cpe-lang:fact-ref name="cpe:/a:dropbear_ssh_project:dropbear_ssh:0.47"/>
        <cpe-lang:fact-ref name="cpe:/a:dropbear_ssh_project:dropbear_ssh:0.48"/>
        <cpe-lang:fact-ref name="cpe:/a:dropbear_ssh_project:dropbear_ssh:0.48.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:dropbear_ssh_project:dropbear_ssh:0.28</vuln:product>
      <vuln:product>cpe:/a:dropbear_ssh_project:dropbear_ssh:0.29</vuln:product>
      <vuln:product>cpe:/a:dropbear_ssh_project:dropbear_ssh:0.30</vuln:product>
      <vuln:product>cpe:/a:dropbear_ssh_project:dropbear_ssh:0.31</vuln:product>
      <vuln:product>cpe:/a:dropbear_ssh_project:dropbear_ssh:0.32</vuln:product>
      <vuln:product>cpe:/a:dropbear_ssh_project:dropbear_ssh:0.33</vuln:product>
      <vuln:product>cpe:/a:dropbear_ssh_project:dropbear_ssh:0.34</vuln:product>
      <vuln:product>cpe:/a:dropbear_ssh_project:dropbear_ssh:0.35</vuln:product>
      <vuln:product>cpe:/a:dropbear_ssh_project:dropbear_ssh:0.36</vuln:product>
      <vuln:product>cpe:/a:dropbear_ssh_project:dropbear_ssh:0.37</vuln:product>
      <vuln:product>cpe:/a:dropbear_ssh_project:dropbear_ssh:0.38</vuln:product>
      <vuln:product>cpe:/a:dropbear_ssh_project:dropbear_ssh:0.39</vuln:product>
      <vuln:product>cpe:/a:dropbear_ssh_project:dropbear_ssh:0.40</vuln:product>
      <vuln:product>cpe:/a:dropbear_ssh_project:dropbear_ssh:0.41</vuln:product>
      <vuln:product>cpe:/a:dropbear_ssh_project:dropbear_ssh:0.42</vuln:product>
      <vuln:product>cpe:/a:dropbear_ssh_project:dropbear_ssh:0.43</vuln:product>
      <vuln:product>cpe:/a:dropbear_ssh_project:dropbear_ssh:0.44</vuln:product>
      <vuln:product>cpe:/a:dropbear_ssh_project:dropbear_ssh:0.44:test1</vuln:product>
      <vuln:product>cpe:/a:dropbear_ssh_project:dropbear_ssh:0.44:test2</vuln:product>
      <vuln:product>cpe:/a:dropbear_ssh_project:dropbear_ssh:0.44:test3</vuln:product>
      <vuln:product>cpe:/a:dropbear_ssh_project:dropbear_ssh:0.44:test4</vuln:product>
      <vuln:product>cpe:/a:dropbear_ssh_project:dropbear_ssh:0.45</vuln:product>
      <vuln:product>cpe:/a:dropbear_ssh_project:dropbear_ssh:0.46</vuln:product>
      <vuln:product>cpe:/a:dropbear_ssh_project:dropbear_ssh:0.47</vuln:product>
      <vuln:product>cpe:/a:dropbear_ssh_project:dropbear_ssh:0.48</vuln:product>
      <vuln:product>cpe:/a:dropbear_ssh_project:dropbear_ssh:0.48.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1099</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:28:03.390-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2018-09-20T08:10:20.660-04:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://matt.ucc.asn.au/dropbear/CHANGES" xml:lang="en">http://matt.ucc.asn.au/dropbear/CHANGES</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22761" xml:lang="en">22761</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0785" xml:lang="en">ADV-2007-0785</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32762" xml:lang="en">dropbear-hostkey-weak-security(32762)</vuln:reference>
    </vuln:references>
    <vuln:summary>dbclient in Dropbear SSH client before 0.49 does not sufficiently warn the user when it detects a hostkey mismatch, which might allow remote attackers to conduct man-in-the-middle attacks.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1100">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:pickle:pickle"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:pickle:pickle</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1100</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:46.343-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2293" xml:lang="en">2293</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://user.ceng.metu.edu.tr/~ahmet/Wiki/Software/pickle/pickle" xml:lang="en">http://user.ceng.metu.edu.tr/~ahmet/Wiki/Software/pickle/pickle</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461145/100/0/threaded" xml:lang="en">20070223 pickle download local file</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22703" xml:lang="en">22703</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0748" xml:lang="en">ADV-2007-0748</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32712" xml:lang="en">pickle-download-directory-traversal(32712)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in download.php in Ahmet Sacan Pickle before 20070301 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1101">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:photostand:photostand:1.2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:photostand:photostand:1.2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1101</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:46.767-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2296" xml:lang="en">2296</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461150/100/0/threaded" xml:lang="en">20070224 Photostand_1.2.0 Multiple Cross Site Scripting</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22706" xml:lang="en">22706</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22707" xml:lang="en">22707</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0752" xml:lang="en">ADV-2007-0752</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32701" xml:lang="en">photostand-index-xss(32701)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Photostand 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) message ("comment") or (2) name field, or the (3) q parameter in a search action in index.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1102">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:photostand:photostand:1.2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:photostand:photostand:1.2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1102</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:47.140-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2296" xml:lang="en">2296</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461150/100/0/threaded" xml:lang="en">20070224 Photostand_1.2.0 Multiple Cross Site Scripting</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0752" xml:lang="en">ADV-2007-0752</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32702" xml:lang="en">photostand-index-path-disclosure(32702)</vuln:reference>
    </vuln:references>
    <vuln:summary>Photostand 1.2.0 allows remote attackers to obtain sensitive information via a ' (quote) character in (1) a PHPSESSID cookie or (2) the id parameter in an article action in index.php, which reveal the path in various error messages.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1103">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:tor:tor:0.1.1.26"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:tor:tor:0.1.1.26</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1103</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:43:18.127-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://archives.seul.org/or/talk/Feb-2007/msg00197.html" xml:lang="en">[or-talk] 20070225 "Low-Resource Routing Attacks Against Anonymous Systems"</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://archives.seul.org/or/talk/Feb-2007/msg00200.html" xml:lang="en">[or-talk] 20070225 Re: "Low-Resource Routing Attacks Against Anonymous Systems"</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://archives.seul.org/or/talk/Feb-2007/msg00202.html" xml:lang="en">[or-talk] 20070225 Re: ISP controlling entry/exti ("Low-Resource Routing Attacks Against Anonymous Systems")</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.cs.colorado.edu/department/publications/reports/docs/CU-CS-1025-07.pdf" xml:lang="en">http://www.cs.colorado.edu/department/publications/reports/docs/CU-CS-1025-07.pdf</vuln:reference>
    </vuln:references>
    <vuln:summary>Tor does not verify a node's uptime and bandwidth advertisements, which allows remote attackers who operate a low resource node to make false claims of greater resources, which places the node into use for many circuits and compromises the anonymity of traffic sources and destinations.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1104">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:php_mip:php_mip:0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php_mip:php_mip:0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1104</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:45.517-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22714" xml:lang="en">22714</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0732" xml:lang="en">ADV-2007-0732</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32672" xml:lang="en">phpmodule-top-file-include(32672)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3374" xml:lang="en">3374</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in top.php in PHP Module Implementation (PHP-MIP) 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the laypath parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1105">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:extreme_phpbb:extreme_phpbb:3.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:extreme_phpbb:extreme_phpbb:3.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1105</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:45.580-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22708" xml:lang="en">22708</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0733" xml:lang="en">ADV-2007-0733</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32685" xml:lang="en">extremephpbb-functions-file-include(32685)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3370" xml:lang="en">3370</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in functions.php in Extreme phpBB (aka phpBB Extreme) 3.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1106">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nomoketos_rules:nomoketos_rules:0.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nomoketos_rules:nomoketos_rules:0.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1106</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:45.657-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22713" xml:lang="en">22713</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0735" xml:lang="en">ADV-2007-0735</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32686" xml:lang="en">nomoketo-functions-file-include(32686)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3373" xml:lang="en">3373</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in includes/functions_nomoketos_rules.php in the NoMoKeTos Rules 0.0.1 module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1107">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:coppermine:coppermine_photo_gallery:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:coppermine:coppermine_photo_gallery:1.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:coppermine:coppermine_photo_gallery:1.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:coppermine:coppermine_photo_gallery:1.3.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:coppermine:coppermine_photo_gallery:1.3</vuln:product>
      <vuln:product>cpe:/a:coppermine:coppermine_photo_gallery:1.3.2</vuln:product>
      <vuln:product>cpe:/a:coppermine:coppermine_photo_gallery:1.3.3</vuln:product>
      <vuln:product>cpe:/a:coppermine:coppermine_photo_gallery:1.3.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1107</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:47.407-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2297" xml:lang="en">2297</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461158/100/0/threaded" xml:lang="en">20070224 Coppermine Photo Gallery 1.3.x Blind SQL Injection Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22709" xml:lang="en">22709</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/27372" xml:lang="en">27372</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32688" xml:lang="en">coppermine-thumbnails-sql-injection(32688)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/39806" xml:lang="en">copperminephoto-thumbnails-sql-injection(39806)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3371" xml:lang="en">3371</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/4950" xml:lang="en">4950</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/4961" xml:lang="en">4961</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in thumbnails.php in Coppermine Photo Gallery (CPG) 1.3.x allows remote authenticated users to execute arbitrary SQL commands via a cpg131_fav cookie.  NOTE: it was later reported that 1.4.10, 1.4.14, and other 1.4.x versions are also affected using similar cookies.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1108">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cs-gallery:cs-gallery:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cs-gallery:cs-gallery:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1108</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:45.800-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22712" xml:lang="en">22712</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0734" xml:lang="en">ADV-2007-0734</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32674" xml:lang="en">csgallery-index-file-include(32674)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3372" xml:lang="en">3372</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in index.php in Christian Schneider CS-Gallery 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the album parameter during a securealbum todo action.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1109">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpwebgallery:phpwebgallery:1.6.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpwebgallery:phpwebgallery:1.6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1109</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:48.220-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2298" xml:lang="en">2298</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461160/100/0/threaded" xml:lang="en">20070224 Phpwebgallery-1.4.1, Multiple Cross Site Scripting</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22711" xml:lang="en">22711</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32687" xml:lang="en">phpwebgallery-register-search-xss(32687)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Phpwebgallery 1.4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) login or (2) mail_address field in Register.php, or the (3) search_author, (4) mode, (5) start_year, (6) end_year, or (7) date_type field in Search.php, a different vulnerability than CVE-2006-1674.  NOTE: 1.6.2 and other versions might also be affected.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1110">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:activecalendar:activecalendar:1.2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:activecalendar:activecalendar:1.2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1110</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:48.703-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2299" xml:lang="en">2299</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461146/100/0/threaded" xml:lang="en">20070224 ActiveCalendar 1.2.0, Multiple vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461313/100/0/threaded" xml:lang="en">20070224 Re: ActiveCalendar 1.2.0, Multiple vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22704" xml:lang="en">22704</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0759" xml:lang="en">ADV-2007-0759</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32691" xml:lang="en">activecalendar-showcode-file-include(32691)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in data/showcode.php in ActiveCalendar 1.2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1111">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:activecalendar:activecalendar:1.2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:activecalendar:activecalendar:1.2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1111</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T12:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:49.203-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2299" xml:lang="en">2299</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461146/100/0/threaded" xml:lang="en">20070224 ActiveCalendar 1.2.0, Multiple vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461313/100/0/threaded" xml:lang="en">20070224 Re: ActiveCalendar 1.2.0, Multiple vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22705" xml:lang="en">22705</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0759" xml:lang="en">ADV-2007-0759</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32690" xml:lang="en">activecalendar-multiple-scripts-xss(32690)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in ActiveCalendar 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the css parameter to (1) flatevents.php, (2) js.php, (3) mysqlevents.php, (4) m_2.php, (5) m_3.php, (6) m_4.php, (7) xmlevents.php, (8) y_2.php, or (9) y_3.php in data/.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1112">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:kaspersky_lab:kaspersky_anti-virus:6.0::windows_workstation"/>
        <cpe-lang:fact-ref name="cpe:/a:kaspersky_lab:kaspersky_internet_security:6.0:maintenance_pack_2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kaspersky_lab:kaspersky_anti-virus:6.0::windows_workstation</vuln:product>
      <vuln:product>cpe:/a:kaspersky_lab:kaspersky_internet_security:6.0:maintenance_pack_2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1112</vuln:cve-id>
    <vuln:published-datetime>2007-04-05T20:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:50.327-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kaspersky.com/technews?id=203038694" xml:lang="en">http://www.kaspersky.com/technews?id=203038694</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/464882/100/0/threaded" xml:lang="en">20070405 ZDI-07-014: Kaspersky Anti-Virus ActiveX Control Unsafe Method Exposure Vulnerablity</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23345" xml:lang="en">23345</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017884" xml:lang="en">1017884</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017885" xml:lang="en">1017885</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1268" xml:lang="en">ADV-2007-1268</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-07-014.html" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-07-014.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33464" xml:lang="en">kaspersky-startuploading-info-disclosure(33464)</vuln:reference>
    </vuln:references>
    <vuln:summary>Kaspersky Anti-Virus 6.0 and Internet Security 6.0 exposes unsafe methods in the (a) AXKLPROD60Lib.KAV60Info (AxKLProd60.dll) and (b) AXKLSYSINFOLib.SysInfo (AxKLSysInfo.dll) ActiveX controls, which allows remote attackers to "download" or delete arbitrary files via crafted arguments to the (1) DeleteFile, (2) StartBatchUploading, (3) StartStrBatchUploading, or (4) StartUploading methods.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1114">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:7.0::vista"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:7.0::vista</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1114</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:50.827-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.hardened-php.net/advisory_032007.142.html" xml:lang="en">http://www.hardened-php.net/advisory_032007.142.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461076/100/0/threaded" xml:lang="en">20070223 Advisory 03/2007: Multiple Browsers Cross Domain Charset Inheritance Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22701" xml:lang="en">22701</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0744" xml:lang="en">ADV-2007-0744</vuln:reference>
    </vuln:references>
    <vuln:summary>The child frames in Microsoft Internet Explorer 7 inherit the default charset from the parent window when a charset is not specified in an HTTP Content-Type header or META tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated using the UTF-7 character set.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1115">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:9.0:beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:9.0:beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:9.01"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:9.02"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:9.10"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:9.12"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:9.20"/>
        <cpe-lang:fact-ref name="cpe:/a:opera:opera_browser:9.20:beta1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:opera:opera_browser:9.0</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:9.0:beta1</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:9.0:beta2</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:9.01</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:9.02</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:9.10</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:9.12</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:9.20</vuln:product>
      <vuln:product>cpe:/a:opera:opera_browser:9.20:beta1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1115</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:51.093-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.hardened-php.net/advisory_032007.142.html" xml:lang="en">http://www.hardened-php.net/advisory_032007.142.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_28_opera.html" xml:lang="en">SUSE-SA:2007:028</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.opera.com/support/search/view/855/" xml:lang="en">http://www.opera.com/support/search/view/855/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461076/100/0/threaded" xml:lang="en">20070223 Advisory 03/2007: Multiple Browsers Cross Domain Charset Inheritance Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22701" xml:lang="en">22701</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017909" xml:lang="en">1017909</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0745" xml:lang="en">ADV-2007-0745</vuln:reference>
    </vuln:references>
    <vuln:summary>The child frames in Opera 9 before 9.20 inherit the default charset from the parent window when a charset is not specified in an HTTP Content-Type header or META tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated using the UTF-7 character set.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1116">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:1.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:firefox:1.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1116</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T18:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:51.530-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2309" xml:lang="en">2309</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.gnucitizen.org/projects/hscan-redux/" xml:lang="en">http://www.gnucitizen.org/projects/hscan-redux/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461006/100/0/threaded" xml:lang="en">20070223 Firefox Cache Hack - Firefox History Hack redux</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461013/100/0/threaded" xml:lang="en">20070223 Re: [Full-disclosure] Firefox Cache Hack - Firefox History Hack redux</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=371375" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=371375</vuln:reference>
    </vuln:references>
    <vuln:summary>The CheckLoadURI function in Mozilla Firefox 1.8 lists the about: URI as a ChromeProtocol and can be loaded via JavaScript, which allows remote attackers to obtain sensitive information by querying the browser's session history.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1117">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:publisher:2007"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:publisher:2007</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1117</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:43:22.467-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://news.com.com/2100-1002_3-6161835.html" xml:lang="en">http://news.com.com/2100-1002_3-6161835.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://research.eeye.com/html/advisories/upcoming/20070216.html" xml:lang="en">http://research.eeye.com/html/advisories/upcoming/20070216.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22702" xml:lang="en">22702</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Publisher 2007 in Microsoft Office 2007 allows remote attackers to execute arbitrary code via unspecified vectors, related to a "file format vulnerability." NOTE: this information is based upon a vague pre-advisory with no actionable information.  However, the advisory is from a reliable source.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1118">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:efiction:efiction:3.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:efiction:efiction:3.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1118</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:45.860-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22682" xml:lang="en">22682</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0708" xml:lang="en">ADV-2007-0708</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32662" xml:lang="en">efiction-pathtosmf-file-include(32662)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3361" xml:lang="en">3361</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple PHP remote file inclusion vulnerabilities in eFiction 3.1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path_to_smf parameter to (1) bridges/SMF/logout.php or (2) get_session_vars.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1119">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:novell:zenworks:7:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:novell:zenworks:7:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1119</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:51:20.143-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22686" xml:lang="en">22686</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0712" xml:lang="en">ADV-2007-0712</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://secure-support.novell.com/KanisaPlatform/Publishing/408/3563780_f.SAL_Public.html" xml:lang="en">https://secure-support.novell.com/KanisaPlatform/Publishing/408/3563780_f.SAL_Public.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://secure-support.novell.com/KanisaPlatform/Publishing/650/3484245_f.SAL_Public.html" xml:lang="en">https://secure-support.novell.com/KanisaPlatform/Publishing/650/3484245_f.SAL_Public.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Novell ZENworks 7 Desktop Management Support Pack 1 before Hot patch 3 (ZDM7SP1HP3) allows remote attackers to upload images to certain folders that were not configured in the "Only allow uploads to the following directories" setting via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1120">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:steema_software:teechart_pro:7.0.1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:steema_software:teechart_pro:7.0.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1120</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:38.890-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22689" xml:lang="en">22689</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32694" xml:lang="en">teechart-activex-file-upload(32694)</vuln:reference>
    </vuln:references>
    <vuln:summary>The (1) Import.LoadFromURL and (2) Export.asText.SaveToFile functions in TeeChart Pro ActiveX control (TeeChart7.ocx) allow remote attackers to download a crafted .tee file to an arbitrary location.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1121">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:zephyrsoft_toolbox:address_book_continued:1.00"/>
        <cpe-lang:fact-ref name="cpe:/a:zephyrsoft_toolbox:address_book_continued:1.01"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:zephyrsoft_toolbox:address_book_continued:1.00</vuln:product>
      <vuln:product>cpe:/a:zephyrsoft_toolbox:address_book_continued:1.01</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1121</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:38.937-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=488406" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=488406</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22685" xml:lang="en">22685</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0715" xml:lang="en">ADV-2007-0715</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32665" xml:lang="en">zephyrsoft-id-sql-injection(32665)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in Mathis Dirksen-Thedens ZephyrSoft Toolbox Address Book Continued (ABC) 1.00 allow remote attackers to execute arbitrary SQL commands via the id parameter to the (1) updateRow and (2) deleteRow functions in functions.php.  NOTE: some of these details are obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1122">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:zephyrsoft_toolbox:address_book_continued:1.00"/>
        <cpe-lang:fact-ref name="cpe:/a:zephyrsoft_toolbox:address_book_continued:1.01"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:zephyrsoft_toolbox:address_book_continued:1.00</vuln:product>
      <vuln:product>cpe:/a:zephyrsoft_toolbox:address_book_continued:1.01</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1122</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:51:20.423-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/downloading.php?group_id=153333&amp;use_mirror=osdn&amp;filename=abc-1.02.zip" xml:lang="en">http://sourceforge.net/project/downloading.php?group_id=153333&amp;use_mirror=osdn&amp;filename=abc-1.02.zip</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22685" xml:lang="en">22685</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0715" xml:lang="en">ADV-2007-0715</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in Mathis Dirksen-Thedens ZephyrSoft Toolbox Address Book Continued (ABC) 1.00 and 1.01 allow remote attackers to execute arbitrary SQL commands via the id parameter to the (1) updateRow and (2) deleteRow functions in functions.php, a variant of a SQL injection issue that was fixed in 1.01.  NOTE: some of these details are obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1123">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:zpanel:zpanel:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:zpanel:zpanel:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1123</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:39.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22683" xml:lang="en">22683</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0710" xml:lang="en">ADV-2007-0710</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32659" xml:lang="en">zpanel-template-file-include(32659)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32680" xml:lang="en">zpanel-zpanel-file-include(32680)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple PHP remote file inclusion vulnerabilities in ZPanel 2.0 allow remote attackers to execute arbitrary PHP code via a URL in (1) the body parameter to templates/ZPanelV2/template.php or (2) the page parameter to zpanel.php.  NOTE: the zpanel.php vector may overlap CVE-2005-0793.2.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1124">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:xeroxer:simple_one-file_gallery:0.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xeroxer:simple_one-file_gallery:0.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1124</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:51.813-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2292" xml:lang="en">2292</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461080/100/0/threaded" xml:lang="en">20070223 Simple one-file gallery</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22700" xml:lang="en">22700</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32654" xml:lang="en">sofg-gallery-file-include(32654)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in gallery.php in XeroXer Simple one-file gallery allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1125">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:xeroxer:simple_one-file_gallery:0.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xeroxer:simple_one-file_gallery:0.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1125</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:52.077-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2292" xml:lang="en">2292</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461080/100/0/threaded" xml:lang="en">20070223 Simple one-file gallery</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22700" xml:lang="en">22700</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0740" xml:lang="en">ADV-2007-0740</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32655" xml:lang="en">sofg-gallery-xss(32655)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in gallery.php in XeroXer Simple one-file gallery allows remote attackers to inject arbitrary web script or HTML via the f parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1126">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:xt-commerce:xt-commerce_community_made_shopping:2.0:rc_1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xt-commerce:xt-commerce_community_made_shopping:2.0:rc_1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1126</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:52.390-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2294" xml:lang="en">2294</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461073/100/0/threaded" xml:lang="en">20070223 xtcommerce local file include</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22698" xml:lang="en">22698</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0746" xml:lang="en">ADV-2007-0746</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32656" xml:lang="en">xtcommerce-index-file-include(32656)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in index.php in xtcommerce allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1127">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:watersweb_shops:shop_kit_plus:initial"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:watersweb_shops:shop_kit_plus:initial</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1127</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:52.703-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2295" xml:lang="en">2295</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461071/100/0/threaded" xml:lang="en">20070223 shopkitplus local file include</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22697" xml:lang="en">22697</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0747" xml:lang="en">ADV-2007-0747</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32660" xml:lang="en">shopkitplus-stylecss-file-include(32660)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in enc/stylecss.php in shopkitplus allows remote attackers to read arbitrary files via a .. (dot dot) in the changetheme parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1128">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:watersweb_shops:shop_kit_plus:initial"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:watersweb_shops:shop_kit_plus:initial</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1128</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:53.047-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2295" xml:lang="en">2295</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461071/100/0/threaded" xml:lang="en">20070223 shopkitplus local file include</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32661" xml:lang="en">shopkitplus-events-stylecss-info-disclosure(32661)</vuln:reference>
    </vuln:references>
    <vuln:summary>shopkitplus allows remote attackers to obtain sensitive information via a request to (1) events.php with a curmonth[]=01 query string or (2) enc/stylecss.php with a changetheme[]= query string, which reveals the path in various error messages.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1129">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mtcms:mtcms:3.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mtcms:mtcms:3.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1129</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:53.327-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461330/100/100/threaded" xml:lang="en">20070223 MTCMS multiple upload vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22690" xml:lang="en">22690</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0755" xml:lang="en">ADV-2007-0755</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple unrestricted file upload vulnerabilities in MTCMS 3.2 allow remote attackers to upload and execute files via (1) an avatar upload in an add_down action, or (2) an add_link action.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1130">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:scipter.ch:gastebuch:2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:scipter.ch:gastebuch:2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1130</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:45.907-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22696" xml:lang="en">22696</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0737" xml:lang="en">ADV-2007-0737</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32657" xml:lang="en">sinapis-gastebuch-sinagb-file-include(32657)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3366" xml:lang="en">3366</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in sinagb.php in Sinapis Gastebuch 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the fuss parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1131">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:scripter.ch:sinapis_forum:2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:scripter.ch:sinapis_forum:2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1131</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:45.957-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22699" xml:lang="en">22699</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0738" xml:lang="en">ADV-2007-0738</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32658" xml:lang="en">sinapisforum-sinapis-file-include(32658)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3367" xml:lang="en">3367</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in sinapis.php in Sinapis Forum 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the fuss parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1132">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mtcms:mtcms:2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mtcms:mtcms:2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1132</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:53.563-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461330/100/100/threaded" xml:lang="en">20070223 MTCMS multiple upload vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22690" xml:lang="en">22690</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0755" xml:lang="en">ADV-2007-0755</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in the "Contact Us" functionality in MTCMS 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) message and (2) title fields.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1133">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:scripter.ch:fcring:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:scripter.ch:fcring:1.31"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:scripter.ch:fcring:1.3</vuln:product>
      <vuln:product>cpe:/a:scripter.ch:fcring:1.31</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1133</vuln:cve-id>
    <vuln:published-datetime>2007-02-26T21:28:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:46.017-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22693" xml:lang="en">22693</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0736" xml:lang="en">ADV-2007-0736</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32653" xml:lang="en">fcring-fcring-file-include(32653)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3365" xml:lang="en">3365</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in fcring.php in FCRing 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the s_fuss parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1134">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:watchtower:watchtower:0.1:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:watchtower:watchtower:0.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:watchtower:watchtower:0.1:alpha</vuln:product>
      <vuln:product>cpe:/a:watchtower:watchtower:0.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1134</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:51:21.657-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=486435&amp;group_id=188798" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=486435&amp;group_id=188798</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22721" xml:lang="en">22721</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0743" xml:lang="en">ADV-2007-0743</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Watchtower (WT) before 0.12 has unknown impact and attack vectors, related to "unauthorized accounts."</vuln:summary>
  </entry>
  <entry id="CVE-2007-1135">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sourceforge:webmplayer:0.6.1-alpha"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sourceforge:webmplayer:0.6.1-alpha</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1135</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:51:21.750-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=486880&amp;group_id=172354" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=486880&amp;group_id=172354</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22726" xml:lang="en">22726</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0742" xml:lang="en">ADV-2007-0742</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in WebMplayer before 0.6.1-Alpha allow remote attackers to execute arbitrary SQL commands via the (1) strid parameter to index.php and the (2) id[0] or other id array index parameter to filecheck.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1136">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:webmplayer:webmplayer:0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:webmplayer:webmplayer:0.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:webmplayer:webmplayer:0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:webmplayer:webmplayer:0.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:webmplayer:webmplayer:0.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:webmplayer:webmplayer:0.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:webmplayer:webmplayer:0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:webmplayer:webmplayer:0.5:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:webmplayer:webmplayer:0.5.1:alpha"/>
        <cpe-lang:fact-ref name="cpe:/a:webmplayer:webmplayer:0.6:alpha"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:webmplayer:webmplayer:0.1</vuln:product>
      <vuln:product>cpe:/a:webmplayer:webmplayer:0.2.1</vuln:product>
      <vuln:product>cpe:/a:webmplayer:webmplayer:0.3</vuln:product>
      <vuln:product>cpe:/a:webmplayer:webmplayer:0.3.1</vuln:product>
      <vuln:product>cpe:/a:webmplayer:webmplayer:0.3.2</vuln:product>
      <vuln:product>cpe:/a:webmplayer:webmplayer:0.3.3</vuln:product>
      <vuln:product>cpe:/a:webmplayer:webmplayer:0.4</vuln:product>
      <vuln:product>cpe:/a:webmplayer:webmplayer:0.5:alpha</vuln:product>
      <vuln:product>cpe:/a:webmplayer:webmplayer:0.5.1:alpha</vuln:product>
      <vuln:product>cpe:/a:webmplayer:webmplayer:0.6:alpha</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1136</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:51:21.860-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://attrition.org/pipermail/vim/2007-February/001399.html" xml:lang="en">20070227 WebMplayer "eval injection" is actually OS command injection</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=486880&amp;group_id=172354" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=486880&amp;group_id=172354</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22726" xml:lang="en">22726</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0742" xml:lang="en">ADV-2007-0742</vuln:reference>
    </vuln:references>
    <vuln:summary>index.php in WebMplayer before 0.6.1-Alpha allows remote attackers to execute arbitrary code via shell metacharacters in an exec function call.  NOTE: some sources have referred to this as eval injection in the param parameter, but CVE source inspection suggests that this is erroneous.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1137">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sourceforge:putmail:.8"/>
        <cpe-lang:fact-ref name="cpe:/a:sourceforge:putmail:.9"/>
        <cpe-lang:fact-ref name="cpe:/a:sourceforge:putmail:.10"/>
        <cpe-lang:fact-ref name="cpe:/a:sourceforge:putmail:.11"/>
        <cpe-lang:fact-ref name="cpe:/a:sourceforge:putmail:.12"/>
        <cpe-lang:fact-ref name="cpe:/a:sourceforge:putmail:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sourceforge:putmail:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sourceforge:putmail:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:sourceforge:putmail:1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sourceforge:putmail:.8</vuln:product>
      <vuln:product>cpe:/a:sourceforge:putmail:.9</vuln:product>
      <vuln:product>cpe:/a:sourceforge:putmail:.10</vuln:product>
      <vuln:product>cpe:/a:sourceforge:putmail:.11</vuln:product>
      <vuln:product>cpe:/a:sourceforge:putmail:.12</vuln:product>
      <vuln:product>cpe:/a:sourceforge:putmail:1.0</vuln:product>
      <vuln:product>cpe:/a:sourceforge:putmail:1.1</vuln:product>
      <vuln:product>cpe:/a:sourceforge:putmail:1.2</vuln:product>
      <vuln:product>cpe:/a:sourceforge:putmail:1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1137</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:39.470-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://putmail.sourceforge.net/home.html" xml:lang="en">http://putmail.sourceforge.net/home.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22718" xml:lang="en">22718</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0753" xml:lang="en">ADV-2007-0753</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32689" xml:lang="en">putmail-tls-password-plaintext(32689)</vuln:reference>
    </vuln:references>
    <vuln:summary>putmail.py in Putmail before 1.4 does not detect when a user attempts to use TLS with a server that does not support it, which causes putmail.py to send the username and password in plaintext while the user believes encryption is in use, and allows remote attackers to obtain sensitive information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1138">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cromosoft:simple_plantilla_php:-"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cromosoft:simple_plantilla_php:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1138</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:53.813-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2332" xml:lang="en">2332</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460913/100/0/threaded" xml:lang="en">20070222 Plantilla PHP Simple</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22669" xml:lang="en">22669</vuln:reference>
    </vuln:references>
    <vuln:summary>Absolute path traversal vulnerability in list_main_pages.php in Cromosoft Simple Plantilla PHP (SPP) allows remote attackers to list arbitrary directories, and read arbitrary files, via an absolute pathname in the nfolder parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1139">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cromosoft:simple_plantilla_php:-"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cromosoft:simple_plantilla_php:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1139</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:54.030-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2332" xml:lang="en">2332</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460913/100/0/threaded" xml:lang="en">20070222 Plantilla PHP Simple</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22669" xml:lang="en">22669</vuln:reference>
    </vuln:references>
    <vuln:summary>Unrestricted file upload vulnerability in Cromosoft Simple Plantilla PHP (SPP) allows remote attackers to upload arbitrary scripts via a filename with a double extension.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1140">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:barekoncept:pheap:-"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:barekoncept:pheap:-</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1140</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:54.237-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2354" xml:lang="en">2354</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460920/100/0/threaded" xml:lang="en">20070222 pheap [edit LFI] vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22670" xml:lang="en">22670</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in edit.php in pheap allows remote attackers to read and modify arbitrary files via a .. (dot dot) in the filename parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1141">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:reamday_enterprises:magic_news_plus:1.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:reamday_enterprises:magic_news_plus:1.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1141</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:54.437-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2334" xml:lang="en">2334</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460902/100/0/threaded" xml:lang="en">20070221 Magic News Plus File Inclusion And Xss Vulnerabilitis</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22661" xml:lang="en">22661</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in preview.php in Magic News Plus 1.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the php_script_path parameter.  NOTE: This issue may overlap CVE-2006-0723.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1142">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:reamday_enterprises:magic_news_plus:1.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:reamday_enterprises:magic_news_plus:1.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1142</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:54.657-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2334" xml:lang="en">2334</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460902/100/0/threaded" xml:lang="en">20070221 Magic News Plus File Inclusion And Xss Vulnerabilitis</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22661" xml:lang="en">22661</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Magic News Plus 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the link_parameters parameter in (1) news.php and (2) n_layouts.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1143">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:jeunes-webmasters:j-web_pics_navigator:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:jeunes-webmasters:j-web_pics_navigator:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:jeunes-webmasters:j-web_pics_navigator:1.0</vuln:product>
      <vuln:product>cpe:/a:jeunes-webmasters:j-web_pics_navigator:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1143</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:54.907-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://forums.avenir-geopolitique.net/viewtopic.php?t=2692" xml:lang="en">http://forums.avenir-geopolitique.net/viewtopic.php?t=2692</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2340" xml:lang="en">2340</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460907/100/0/threaded" xml:lang="en">20070222 Pics Navigator Directory Traversal Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32646" xml:lang="en">picsnavigator-dir-directory-traversal(32646)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in pn-menu.php in J-Web Pics Navigator 1.0 allows remote attackers to list arbitrary directories via a .. (dot dot) in the dir parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1144">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:comscripts:j-web_pics_navigator:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:comscripts:j-web_pics_navigator:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:comscripts:j-web_pics_navigator:1.0</vuln:product>
      <vuln:product>cpe:/a:comscripts:j-web_pics_navigator:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1144</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:55.157-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://forums.avenir-geopolitique.net/viewtopic.php?t=2692" xml:lang="en">http://forums.avenir-geopolitique.net/viewtopic.php?t=2692</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2340" xml:lang="en">2340</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460907/100/0/threaded" xml:lang="en">20070222 Pics Navigator Directory Traversal Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22681" xml:lang="en">22681</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0711" xml:lang="en">ADV-2007-0711</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32646" xml:lang="en">picsnavigator-dir-directory-traversal(32646)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in jwpn-photos.php in J-Web Pics Navigator 2.0 allows remote attackers to list arbitrary directories via a .. (dot dot) in the dir parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1145">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:kayako:esupport:3.00.13"/>
        <cpe-lang:fact-ref name="cpe:/a:kayako:esupport:3.04.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kayako:esupport:3.00.13</vuln:product>
      <vuln:product>cpe:/a:kayako:esupport:3.04.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1145</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:55.577-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2335" xml:lang="en">2335</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460591/100/0/threaded" xml:lang="en">20070219 ESupport Multiple HTML Injection Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22631" xml:lang="en">22631</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0717" xml:lang="en">ADV-2007-0717</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Kayako SupportSuite - ESupport 3.00.13 and 3.04.10 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to a (1) lostpassword or (2) register action in index.php, (3) unspecified vectors in the Submit form in a submit action in index.php, and (4) the user's name in index.php; and (5) allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to the Admin and Staff Control Panel. NOTE: this might issue overlap CVE-2004-1412, CVE-2005-0487, or CVE-2005-0842.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1146">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:delmaa.com:arabhost"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:delmaa.com:arabhost</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1146</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:55.877-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://attrition.org/pipermail/vim/2007-February/001396.html" xml:lang="en">20070227 Verified: arabhost function.php RFI</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2339" xml:lang="en">2339</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460933/100/0/threaded" xml:lang="en">20070222 Hasadya Raed</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in function.php in arabhost allows remote attackers to execute arbitrary PHP code via a URL in the adminfolder parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1147">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:hbm:hbm"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hbm:hbm</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1147</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:56.063-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2339" xml:lang="en">2339</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460933/100/0/threaded" xml:lang="en">20070222 Hasadya Raed</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in view.php in hbm allows remote attackers to execute arbitrary PHP code via a URL in the hbmpath parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1148">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:lovecms:lovecms:1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:lovecms:lovecms:1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1148</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:56.187-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2338" xml:lang="en">2338</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460917/100/0/threaded" xml:lang="en">20070222 LoveCMS 1.4 multiple vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22675" xml:lang="en">22675</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0716" xml:lang="en">ADV-2007-0716</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in install/index.php in LoveCMS 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the step parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1149">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:lovecms:lovecms:1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:lovecms:lovecms:1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1149</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:56.423-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2338" xml:lang="en">2338</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460917/100/0/threaded" xml:lang="en">20070222 LoveCMS 1.4 multiple vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22675" xml:lang="en">22675</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0716" xml:lang="en">ADV-2007-0716</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple directory traversal vulnerabilities in LoveCMS 1.4 allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the step parameter to install/index.php or (2) the load parameter to the top-level URI.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1150">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:lovecms:lovecms:1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:lovecms:lovecms:1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1150</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:56.673-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2338" xml:lang="en">2338</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460917/100/0/threaded" xml:lang="en">20070222 LoveCMS 1.4 multiple vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22675" xml:lang="en">22675</vuln:reference>
    </vuln:references>
    <vuln:summary>Unrestricted file upload vulnerability in LoveCMS 1.4 allows remote authenticated administrators to upload arbitrary files to /modules/content/pictures/tmp/.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1151">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:lovecms:lovecms:1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:lovecms:lovecms:1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1151</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:56.937-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2338" xml:lang="en">2338</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460917/100/0/threaded" xml:lang="en">20070222 LoveCMS 1.4 multiple vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22675" xml:lang="en">22675</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0716" xml:lang="en">ADV-2007-0716</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in LoveCMS 1.4 allows remote attackers to inject arbitrary web script or HTML via the id parameter to the top-level URI, possibly related to a SQL error.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1152">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:pyrophobia:pyrophobia:2.1.3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:pyrophobia:pyrophobia:2.1.3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1152</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:46.080-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-22"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22667" xml:lang="en">22667</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/33861" xml:lang="en">33861</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/8095" xml:lang="en">8095</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple directory traversal vulnerabilities in Pyrophobia 2.1.3.1 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) act or (2) pid parameter to the top-level URI (index.php), or the (3) action parameter to admin/index.php.  NOTE: some of these details are obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1153">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:cutephp:cutenews:1.3.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cutephp:cutenews:1.3.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1153</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:43:31.093-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22674" xml:lang="en">22674</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple PHP remote file inclusion vulnerabilities in CutePHP CuteNews 1.3.6 allow remote attackers to execute arbitrary PHP code via unspecified vectors.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: issue might overlap CVE-2004-1660 or CVE-2006-4445.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1154">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:webspell:webspell"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:webspell:webspell</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1154</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:57.250-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2337" xml:lang="en">2337</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460937/100/0/threaded" xml:lang="en">20070222 WebSpell > 4.0 Authentication Bypass and arbitrary code execution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32669" xml:lang="en">webspell-login-sql-injection(32669)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in webSPELL allows remote attackers to execute arbitrary SQL commands via a ws_auth cookie, a different vulnerability than CVE-2006-4782.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1155">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:webspell:webspell"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:webspell:webspell</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1155</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:57.517-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2337" xml:lang="en">2337</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460937/100/0/threaded" xml:lang="en">20070222 WebSpell > 4.0 Authentication Bypass and arbitrary code execution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32670" xml:lang="en">webspell-addsquad-file-upload(32670)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unrestricted file upload vulnerability in webSPELL allows remote authenticated administrators to upload and execute arbitrary PHP code via the add squad feature.  NOTE: this issue may be an administrative feature, in which case this CVE may be REJECTED.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1156">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:man_machine_systems:jbrowser"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:man_machine_systems:jbrowser</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1156</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:57.783-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://forums.avenir-geopolitique.net/viewtopic.php?t=2693" xml:lang="en">http://forums.avenir-geopolitique.net/viewtopic.php?t=2693</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2370" xml:lang="en">2370</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1008909" xml:lang="en">1008909</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460923/100/0/threaded" xml:lang="en">20070222 JBrowser acces to admin/config files</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461298/100/100/threaded" xml:lang="en">20070223 JBrowser Acces to Admin Panel Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/9537" xml:lang="en">9537</vuln:reference>
    </vuln:references>
    <vuln:summary>JBrowser allows remote attackers to bypass authentication and access certain administrative capabilities via a direct request for _admin/.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1157">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:jboss:jboss"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:jboss:jboss</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1157</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:58.267-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-352"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460934/100/0/threaded" xml:lang="en">20070222 JBoss jmx-console CSRF</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461004/100/0/threaded" xml:lang="en">20070223 Re: JBoss jmx-console CSRF</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32673" xml:lang="en">jboss-jmxconsole-csrf(32673)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site request forgery (CSRF) vulnerability in jmx-console/HtmlAdaptor in JBoss allows remote attackers to perform privileged actions as administrators via certain MBean operations, a different vulnerability than CVE-2006-3733.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1158">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:postnuke_software_foundation:pagesetter:6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:postnuke_software_foundation:pagesetter:6.3.0:beta_5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:postnuke_software_foundation:pagesetter:6.2</vuln:product>
      <vuln:product>cpe:/a:postnuke_software_foundation:pagesetter:6.3.0:beta_5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1158</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:58.547-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://marc.info/?l=full-disclosure&amp;m=117251821622820&amp;w=2" xml:lang="en">20070226 SEC Consult SA-20070226-0 :: File Disclosure in</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://marc.info/?l=full-disclosure&amp;m=117256698219502&amp;w=2" xml:lang="en">20070227 Re:SEC Consult SA-20070226-0 :: File Disclosure</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2336" xml:lang="en">2336</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.elfisk.dk/index.php?module=pagesetter&amp;func=viewpub&amp;tid=7&amp;pid=125" xml:lang="en">http://www.elfisk.dk/index.php?module=pagesetter&amp;func=viewpub&amp;tid=7&amp;pid=125</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461339/100/0/threaded" xml:lang="en">20070226 SEC Consult SA-20070226-0 :: File Disclosure in Pagesetter for PostNuke</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22733" xml:lang="en">22733</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0758" xml:lang="en">ADV-2007-0758</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32695" xml:lang="en">pagesetter-index-directory-traversal(32695)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in index.php in the Pagesetter 6.2.0 through 6.3.0 beta 5 module for PostNuke allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1159">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:pyrophobia:pyrophobia:2.1.3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:pyrophobia:pyrophobia:2.1.3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1159</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:43:32.453-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22667" xml:lang="en">22667</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in modules/out.php in Pyrophobia 2.1.3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1160">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:webspell:webspell:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:webspell:webspell:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1160</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:59.237-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2337" xml:lang="en">2337</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460937/100/0/threaded" xml:lang="en">20070222 WebSpell > 4.0 Authentication Bypass and arbitrary code execution</vuln:reference>
    </vuln:references>
    <vuln:summary>webSPELL 4.0, and possibly later versions, allows remote attackers to bypass authentication via a ws_auth cookie, a different vulnerability than CVE-2006-4782.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1161">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:call_center_software:call_center_software:0.93"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:call_center_software:call_center_software:0.93</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1161</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:59.533-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2333" xml:lang="en">2333</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-February/001378.html" xml:lang="en">20070222 [TRUE] Call Center Software - Remote Xss Post Exploit -</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460797/100/0/threaded" xml:lang="en">20070221 Call Center Software - Remote Xss Post Exploit -</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in call_entry.php in Call Center Software 0,93 allows remote attackers to inject arbitrary web script or HTML via the problem_desc parameter, as demonstrated by the ONLOAD attribute of a BODY element.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1162">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:common_controls_replacement_project:browsedialog_server"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:common_controls_replacement_project:browsedialog_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1162</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:46.143-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22645" xml:lang="en">22645</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/data/vulnerabilities/exploits/22645.html" xml:lang="en">http://www.securityfocus.com/data/vulnerabilities/exploits/22645.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3350" xml:lang="en">3350</vuln:reference>
    </vuln:references>
    <vuln:summary>A certain ActiveX control in the Common Controls Replacement Project (CCRP) CCRP BrowseDialog Server (ccrpbds6.dll) allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long (1) IsFolderAvailable or (2) RootFolder property value, different vectors than CVE-2007-0371.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1163">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:webspell:webspell:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:webspell:webspell:4.01.00"/>
        <cpe-lang:fact-ref name="cpe:/a:webspell:webspell:4.01.01"/>
        <cpe-lang:fact-ref name="cpe:/a:webspell:webspell:4.01.02"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:webspell:webspell:4.0</vuln:product>
      <vuln:product>cpe:/a:webspell:webspell:4.01.00</vuln:product>
      <vuln:product>cpe:/a:webspell:webspell:4.01.01</vuln:product>
      <vuln:product>cpe:/a:webspell:webspell:4.01.02</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1163</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:46.207-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22659" xml:lang="en">22659</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0714" xml:lang="en">ADV-2007-0714</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3351" xml:lang="en">3351</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in printview.php in webSPELL 4.01.02 and earlier allows remote attackers to execute arbitrary SQL commands via the topic parameter, a different vector than CVE-2007-1019, CVE-2006-5388, and CVE-2006-4783.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1164">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:dbscripts:dbimagegallery:1.2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:dbscripts:dbimagegallery:1.2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1164</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:36:59.813-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461741/100/0/threaded" xml:lang="en">20070302 Remote File Include In DBImageGallery</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/462142/100/0/threaded" xml:lang="en">20070305 Re: Remote File Include In DBImageGallery</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22657" xml:lang="en">22657</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0692" xml:lang="en">ADV-2007-0692</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32612" xml:lang="en">dbimagegallery-donsimg-file-include(32612)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3353" xml:lang="en">3353</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple PHP remote file inclusion vulnerabilities in DBImageGallery 1.2.2 allow remote attackers to execute arbitrary PHP code via a URL in the donsimg_base_path parameter to (1) attributes.php, (2) images.php, or (3) scan.php in admin/; or (4) attributes.php, (5) db_utils.php, (6) images.php, (7) utils.php, or (8) values.php in includes/.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1165">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:dbscripts:dbguestbook:1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:dbscripts:dbguestbook:1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1165</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:46.330-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22658" xml:lang="en">22658</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0693" xml:lang="en">ADV-2007-0693</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3354" xml:lang="en">3354</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple PHP remote file inclusion vulnerabilities in DBGuestbook 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the dbs_base_path parameter to (1) utils.php, (2) guestbook.php, or (3) views.php in includes/.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1166">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nabocorp:nabopoll:1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nabocorp:nabopoll:1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1166</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:00.877-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://attrition.org/pipermail/vim/2007-February/001379.html" xml:lang="en">20070222 [TRUE] Nabopoll Blind SQL Injection vulnerabilies</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2372" xml:lang="en">2372</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460765/100/0/threaded" xml:lang="en">20070221 Nabopoll Blind SQL Injection vulnerabilies</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22649" xml:lang="en">22649</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3355" xml:lang="en">3355</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in result.php in Nabopoll 1.2 allows remote attackers to execute arbitrary SQL commands via the surv parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1167">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:dzcp:dev%21l%27z_clanportal:1.4.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:dzcp:dev%21l%27z_clanportal:1.4.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1167</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:46.440-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.dzcp.de/inc/tinymce_files/Downloads/dzcp_update/notes_1.4.6.txt" xml:lang="en">http://www.dzcp.de/inc/tinymce_files/Downloads/dzcp_update/notes_1.4.6.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22660" xml:lang="en">22660</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0695" xml:lang="en">ADV-2007-0695</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3357" xml:lang="en">3357</vuln:reference>
    </vuln:references>
    <vuln:summary>inc/filebrowser/browser.php in deV!L`z Clanportal (DZCP) 1.4.5 and earlier allows remote attackers to obtain MySQL data via the inc/mysql.php value of the file parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1168">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:serverprotect:1.3::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:serverprotect:1.25_2007-02-16::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:serverprotect:2.5::linux"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:trend_micro:serverprotect:1.3::linux</vuln:product>
      <vuln:product>cpe:/a:trend_micro:serverprotect:1.25_2007-02-16::linux</vuln:product>
      <vuln:product>cpe:/a:trend_micro:serverprotect:2.5::linux</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1168</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:51:24.953-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=477" xml:lang="en">20070221 Trend Micro ServerProtect Web Interface Authorization Bypass Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017685" xml:lang="en">1017685</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22662" xml:lang="en">22662</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.trendmicro.com/download/product.asp?productid=20" xml:lang="en">http://www.trendmicro.com/download/product.asp?productid=20</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0691" xml:lang="en">ADV-2007-0691</vuln:reference>
    </vuln:references>
    <vuln:summary>Trend Micro ServerProtect for Linux (SPLX) 1.25, 1.3, and 2.5 before 20070216 allows remote attackers to access arbitrary web pages and reconfigure the product via HTTP requests with the splx_2376_info cookie to the web interface port (14942/tcp).</vuln:summary>
  </entry>
  <entry id="CVE-2007-1169">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:serverprotect:1.25_2007-02-16::linux"/>
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:serverprotect:1.25_2007-02-16:1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:trend_micro:serverprotect:1.25_2007-02-16::linux</vuln:product>
      <vuln:product>cpe:/a:trend_micro:serverprotect:1.25_2007-02-16:1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1169</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T17:19:49.940-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-03-06T09:35:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.trendmicro.com/download/product.asp?productid=20" xml:lang="en">http://www.trendmicro.com/download/product.asp?productid=20</vuln:reference>
    </vuln:references>
    <vuln:summary>The web interface in Trend Micro ServerProtect for Linux (SPLX) 1.25, 1.3, and 2.5 before 20070216 accepts logon requests through unencrypted HTTP, which might allow remote attackers to obtain credentials by sniffing the network.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1170">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:simbin:gt_legends:1.1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:simbin:gtr_-_fia_get_racing_game:1.5.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:simbin:gtr_2:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:simbin:race_-_the_wtcc_game:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:simbin:gt_legends:1.1.0.0</vuln:product>
      <vuln:product>cpe:/a:simbin:gtr_-_fia_get_racing_game:1.5.0.0</vuln:product>
      <vuln:product>cpe:/a:simbin:gtr_2:1.1</vuln:product>
      <vuln:product>cpe:/a:simbin:race_-_the_wtcc_game:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1170</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:01.283-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://aluigi.altervista.org/adv/simbinzero-adv.txt" xml:lang="en">http://aluigi.altervista.org/adv/simbinzero-adv.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2369" xml:lang="en">2369</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460762/100/0/threaded" xml:lang="en">20070221 Players disconnection in Simbin racing games</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22651" xml:lang="en">22651</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0696" xml:lang="en">ADV-2007-0696</vuln:reference>
    </vuln:references>
    <vuln:summary>SimBin GTR - FIA GT Racing Game 1.5.0.0 and earlier, GT Legends 1.1.0.0 and earlier, GTR 2 1.1 and earlier, and RACE - The WTCC Game 1.0 and earlier allow remote attackers to cause a denial of service (client disconnection) via an empty UDP packet to the server port.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1171">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nukescripts:nukesentinel:2.5.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nukescripts:nukesentinel:2.5.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1171</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:01.657-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2344" xml:lang="en">2344</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-September/001806.html" xml:lang="en">20070928 CVE-2007-5125 - dupe</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.nukescripts.net/index.php?op=NEArticle&amp;sid=4076" xml:lang="en">http://www.nukescripts.net/index.php?op=NEArticle&amp;sid=4076</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460628/100/0/threaded" xml:lang="en">20070220 NukeSentinel 2.5.05 (nsbypass.php) Blind SQL Injection Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/480575/100/0/threaded" xml:lang="en">20070925 [waraxe-2007-SA#053] - Critical Sql Injection in NukeSentinel 2.5.11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/480994/100/0/threaded" xml:lang="en">20070928 Re: [waraxe-2007-SA#053] - Critical Sql Injection in NukeSentinel 2.5.11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22629" xml:lang="en">22629</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/25805" xml:lang="en">25805</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.waraxe.us/advisory-53.html" xml:lang="en">http://www.waraxe.us/advisory-53.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32582" xml:lang="en">nukesentinel-nsbypass-sql-injection(32582)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3337" xml:lang="en">3337</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in includes/nsbypass.php in NukeSentinel 2.5.05, 2.5.11, and other versions before 2.5.12 allows remote attackers to execute arbitrary SQL commands via an admin cookie.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1172">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nukescripts:nukesentinel:2.5.05"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nukescripts:nukesentinel:2.5.05</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1172</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:02.673-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://attrition.org/pipermail/vim/2007-March/001429.html" xml:lang="en">20070314 SQL injection (x2) in NukeSentinel</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2341" xml:lang="en">2341</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460599/100/0/threaded" xml:lang="en">20070220 NukeSentinel 2.5.05 (nukesentinel.php) File Disclosure Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3338" xml:lang="en">3338</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in nukesentinel.php in NukeSentinel 2.5.05, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header, aka the "File Disclosure Exploit."</vuln:summary>
  </entry>
  <entry id="CVE-2007-1173">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:centennial:discovery:2006_featurepack1"/>
        <cpe-lang:fact-ref name="cpe:/a:numara:asset_manager:8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:symantec:discovery:6.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:centennial:discovery:2006_featurepack1</vuln:product>
      <vuln:product>cpe:/a:numara:asset_manager:8.0</vuln:product>
      <vuln:product>cpe:/a:symantec:discovery:6.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1173</vuln:cve-id>
    <vuln:published-datetime>2007-05-16T18:30:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:40.047-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/24002" xml:lang="en">24002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018072" xml:lang="en">1018072</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1832" xml:lang="en">ADV-2007-1832</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1833" xml:lang="en">ADV-2007-1833</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1834" xml:lang="en">ADV-2007-1834</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/34313" xml:lang="en">xferwan-tcp-bo(34313)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in the CentennialIPTransferServer service (XFERWAN.EXE), as used by (1) Centennial Discovery 2006 Feature Pack 1, (2) Numara Asset Manager 8.0, and (3) Symantec Discovery 6.5, allow remote attackers to execute arbitrary code via long strings in a crafted TCP packet.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1174">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1174</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:40.093-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22563" xml:lang="en">22563</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0605" xml:lang="en">ADV-2007-0605</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=251" xml:lang="en">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=251</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32506" xml:lang="en">webapporg-net-profileedit-xss(32506)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in WebAPP before 20070214 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to unspecified fields in user Profiles.  NOTE: some of these details are obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1175">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1175</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:51:25.937-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22563" xml:lang="en">22563</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0604" xml:lang="en">ADV-2007-0604</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=249" xml:lang="en">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=249</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in an admin feature in WebAPP before 20070209 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1176">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1176</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:40.157-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22563" xml:lang="en">22563</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0604" xml:lang="en">ADV-2007-0604</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250" xml:lang="en">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32498" xml:lang="en">webapp-statisticslogviewer-xss(32498)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32499" xml:lang="en">webapp-searchresultspages-xss(32499)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32526" xml:lang="en">webapp-gallery-feedback-xss(32526)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in WebAPP before 0.9.9.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) Gallery Comments pages, (2) Feedback pages, (3) Search Results pages, and (4) the Statistics Log viewer.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1177">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.1</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.2</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.2.1</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.3</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.3.1</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.3.2</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1177</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:51:26.143-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22563" xml:lang="en">22563</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0604" xml:lang="en">ADV-2007-0604</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250" xml:lang="en">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250</vuln:reference>
    </vuln:references>
    <vuln:summary>WebAPP before 0.9.9.5 does not properly filter certain characters in contexts related to (1) the query string, (2) Profiles, (3) the Forum Post icon field, (4) the Edit Profile, and (5) the Gallery, which has unknown impact and remote attack vectors, possibly related to cross-site scripting (XSS).</vuln:summary>
  </entry>
  <entry id="CVE-2007-1178">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1178</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:51:26.267-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22563" xml:lang="en">22563</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0604" xml:lang="en">ADV-2007-0604</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250" xml:lang="en">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250</vuln:reference>
    </vuln:references>
    <vuln:summary>WebAPP before 0.9.9.5 does not check access in certain contexts related to (1) Calendar Administration, (2) Instant Messages Administration, and (3) the Image Uploader, which has unknown impact and attack vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1179">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1179</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:51:26.347-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22563" xml:lang="en">22563</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0604" xml:lang="en">ADV-2007-0604</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250" xml:lang="en">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250</vuln:reference>
    </vuln:references>
    <vuln:summary>WebAPP before 0.9.9.5 does not properly manage e-mail addresses in certain contexts related to (1) the Recommend feature, Email Article (2) senders and (3) recipients, (4) New User Approval, (5) Edit Profiles, (6) the Newsletter Subscription form, (7) the Recommend form, and (8) sending of articles, which has unknown impact, and remote attack vectors related to spam attacks and possibly other attacks.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1180">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1180</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:51:26.437-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22563" xml:lang="en">22563</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0604" xml:lang="en">ADV-2007-0604</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250" xml:lang="en">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250</vuln:reference>
    </vuln:references>
    <vuln:summary>WebAPP before 0.9.9.5 does not check referrers in certain forms, which might facilitate remote cross-site request forgery (CSRF) attacks or have other unknown impact.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1181">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.1</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.2</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.2.1</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.3</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.3.1</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.3.2</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1181</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:51:26.547-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22563" xml:lang="en">22563</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0604" xml:lang="en">ADV-2007-0604</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250" xml:lang="en">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250</vuln:reference>
    </vuln:references>
    <vuln:summary>WebAPP before 0.9.9.5 passes (1) Unused Informations and (2) the username through Edit Profile forms, which has unknown impact and attack vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1182">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.1</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.2</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.2.1</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.3</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.3.1</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.3.2</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1182</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:51:26.657-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22563" xml:lang="en">22563</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0604" xml:lang="en">ADV-2007-0604</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250" xml:lang="en">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250</vuln:reference>
    </vuln:references>
    <vuln:summary>WebAPP before 0.9.9.5 allows remote Guest users to edit a Guest profile, which has unknown impact.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1183">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1183</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:51:26.750-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22563" xml:lang="en">22563</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0604" xml:lang="en">ADV-2007-0604</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250" xml:lang="en">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250</vuln:reference>
    </vuln:references>
    <vuln:summary>WebAPP before 0.9.9.5 allows remote authenticated users to spoof another user's Real Name via whitespace, which has unknown impact and attack vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1184">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.1</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.2</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.2.1</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.3</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.3.1</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.3.2</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1184</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:51:26.847-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-16"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22563" xml:lang="en">22563</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0604" xml:lang="en">ADV-2007-0604</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250" xml:lang="en">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250</vuln:reference>
    </vuln:references>
    <vuln:summary>The default configuration of WebAPP before 0.9.9.5 has a CAPTCHA setting of "no," which makes it easier for automated programs to submit false data.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1185">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.1</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.2</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.2.1</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.3</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.3.1</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.3.2</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1185</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:51:26.937-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22563" xml:lang="en">22563</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0604" xml:lang="en">ADV-2007-0604</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250" xml:lang="en">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250</vuln:reference>
    </vuln:references>
    <vuln:summary>The (1) Search, (2) Edit Profile, (3) Recommend, and (4) User Approval forms in WebAPP before 0.9.9.5 use hidden inputs, which has unknown impact and remote attack vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1186">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.1</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.2</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.2.1</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.3</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.3.1</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.3.2</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1186</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:51:27.033-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22563" xml:lang="en">22563</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0604" xml:lang="en">ADV-2007-0604</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250" xml:lang="en">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250</vuln:reference>
    </vuln:references>
    <vuln:summary>WebAPP before 0.9.9.5 does not "censor" the Latest Member real name, which has unknown impact.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1187">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.1</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.2</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.2.1</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.3</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.3.1</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.3.2</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1187</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:51:27.127-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22563" xml:lang="en">22563</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0604" xml:lang="en">ADV-2007-0604</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250" xml:lang="en">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250</vuln:reference>
    </vuln:references>
    <vuln:summary>WebAPP before 0.9.9.5 allows remote authenticated users, without admin privileges, to obtain sensitive information via (1) the Forum Archive feature and (2) Recent Searches.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1188">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.1</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.2</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.2.1</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.3</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.3.1</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.3.2</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1188</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:51:27.187-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22563" xml:lang="en">22563</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0604" xml:lang="en">ADV-2007-0604</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250" xml:lang="en">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250</vuln:reference>
    </vuln:references>
    <vuln:summary>WebAPP before 0.9.9.5 allows remote attackers to submit Search form input that is not checked for (1) composition or (2) length, which has unknown impact, possibly related to "search form hijacking".</vuln:summary>
  </entry>
  <entry id="CVE-2007-1189">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:bell_labs:plan_9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:bell_labs:plan_9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1189</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:46.610-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://kernelspace.us/itheft.c" xml:lang="en">http://kernelspace.us/itheft.c</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.immunitysec.com/pipermail/dailydave/2007-February/004118.html" xml:lang="en">[dailydave] 20070227 Wow, free kernel zero day?</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22749" xml:lang="en">22749</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3383" xml:lang="en">3383</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in the envwrite function in the Alcatel-Lucent Bell Labs Plan 9 kernel allows local users to overwrite certain memory addresses with kernel memory via a large n argument, as demonstrated by (1) modifying the iseve function to gain privileges and (2) making the devpermcheck function grant unrestricted device permissions.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1190">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bsalsa:embeddedwb_web_browser"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bsalsa:embeddedwb_web_browser</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1190</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:43:42.127-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22755" xml:lang="en">22755</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the EmbeddedWB Web Browser ActiveX control allows remote attackers to execute arbitrary code via unspecified vectors.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1191">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:quicksilver:del.icio.us_module:8f"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:quicksilver:del.icio.us_module:8f</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1191</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:40.220-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052722.html" xml:lang="en">20070228 Quicksilver Social Bookmark plugin v.8F: password in clear text</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2368" xml:lang="en">2368</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22752" xml:lang="en">22752</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32721" xml:lang="en">socialbookmarks-password-plaintext(32721)</vuln:reference>
    </vuln:references>
    <vuln:summary>The Social Bookmarks (del.icio.us) plug-in 8F in Quicksilver writes usernames and passwords in plaintext to the /Library/Logs/Console/UID/Console.log file, which allows local users to obtain sensitive information by reading this file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1192">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:hyperbook:guestbook:1.30"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hyperbook:guestbook:1.30</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1192</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:43:42.547-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://downloads.securityfocus.com/vulnerabilities/exploits/22754.py" xml:lang="en">http://downloads.securityfocus.com/vulnerabilities/exploits/22754.py</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22754" xml:lang="en">22754</vuln:reference>
    </vuln:references>
    <vuln:summary>Thomas R. Pasawicz HyperBook Guestbook 1.30 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download an admin password hash via a direct request for data/gbconfiguration.dat.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1193">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:orangehrm:orangehrm:2.1:alpha_4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:orangehrm:orangehrm:2.1:alpha_4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1193</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:51:29.847-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1656000&amp;group_id=156477&amp;atid=799942" xml:lang="en">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1656000&amp;group_id=156477&amp;atid=799942</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22756" xml:lang="en">22756</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0781" xml:lang="en">ADV-2007-0781</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple unspecified vulnerabilities in the Login page in OrangeHRM before 20070212 have unknown impact and attack vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1194">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:norman:norman_sandbox_analyzer"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:norman:norman_sandbox_analyzer</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1194</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:03.047-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.ntsecurity.nu/onmymind/2007/2007-02-27.html" xml:lang="en">http://www.ntsecurity.nu/onmymind/2007/2007-02-27.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461555/100/0/threaded" xml:lang="en">20070228 Evading the Norman SandBox Analyzer</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461804/100/100/threaded" xml:lang="en">20070302 Re: Evading the Norman SandBox Analyzer</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461805/100/100/threaded" xml:lang="en">20070303 Re: Evading the Norman SandBox Analyzer</vuln:reference>
    </vuln:references>
    <vuln:summary>Norman SandBox Analyzer does not use the proper range for Interrupt Descriptor Table (IDT) entries, which allows local users to determine that the local machine is an emulator, or a similar environment not based on a physical Intel processor, which allows attackers to produce malware that is more difficult to analyze.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1195">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:dxmsoft:xm_easy_personal_ftp_server:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:dxmsoft:xm_easy_personal_ftp_server:5.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:dxmsoft:xm_easy_personal_ftp_server:5.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:dxmsoft:xm_easy_personal_ftp_server:5.0.1</vuln:product>
      <vuln:product>cpe:/a:dxmsoft:xm_easy_personal_ftp_server:5.2.1</vuln:product>
      <vuln:product>cpe:/a:dxmsoft:xm_easy_personal_ftp_server:5.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1195</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:46.657-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://downloads.securityfocus.com/vulnerabilities/exploits/22747.pl" xml:lang="en">http://downloads.securityfocus.com/vulnerabilities/exploits/22747.pl</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22747" xml:lang="en">22747</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0786" xml:lang="en">ADV-2007-0786</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3385" xml:lang="en">3385</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in XM Easy Personal FTP Server 5.3.0 allow remote attackers to execute arbitrary code via unspecified vectors. NOTE: this issue might overlap CVE-2006-2225, CVE-2006-2226, or CVE-2006-5728.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1196">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:citrix:presentation_server_client:9.200::windows"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:citrix:presentation_server_client:9.200::windows</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1196</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:40.283-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.citrix.com/article/CTX112589" xml:lang="en">http://support.citrix.com/article/CTX112589</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/798364" xml:lang="en">VU#798364</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22762" xml:lang="en">22762</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017712" xml:lang="en">1017712</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0784" xml:lang="en">ADV-2007-0784</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32754" xml:lang="en">citrix-ica-code-execution(32754)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Citrix Presentation Server Client for Windows before 10.0 allows remote web sites to execute arbitrary code via unspecified vectors, related to the implementation of ICA connectivity through proxy servers.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1197">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:epiware:epiware:4.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:epiware:epiware:4.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:epiware:epiware:4.6.6</vuln:product>
      <vuln:product>cpe:/a:epiware:epiware:4.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1197</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:43:44.187-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/forum/forum.php?forum_id=669653" xml:lang="en">http://sourceforge.net/forum/forum.php?forum_id=669653</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple unspecified vulnerabilities in Epiware before 4.7.5 have unknown impact and attack vectors, possibly related to cross-site scripting (XSS) and other unspecified issues.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1198">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:taskfreak:taskfreak:0.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:taskfreak:taskfreak:0.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:taskfreak:taskfreak:0.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:taskfreak:taskfreak:0.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:taskfreak:taskfreak:0.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:taskfreak:taskfreak:0.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:taskfreak:taskfreak:0.5.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:taskfreak:taskfreak:0.5.0</vuln:product>
      <vuln:product>cpe:/a:taskfreak:taskfreak:0.5.1</vuln:product>
      <vuln:product>cpe:/a:taskfreak:taskfreak:0.5.2</vuln:product>
      <vuln:product>cpe:/a:taskfreak:taskfreak:0.5.3</vuln:product>
      <vuln:product>cpe:/a:taskfreak:taskfreak:0.5.4</vuln:product>
      <vuln:product>cpe:/a:taskfreak:taskfreak:0.5.5</vuln:product>
      <vuln:product>cpe:/a:taskfreak:taskfreak:0.5.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1198</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:43:44.360-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.taskfreak.com/versions.html" xml:lang="en">http://www.taskfreak.com/versions.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in TaskFreak! before 0.5.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly a variant of CVE-2007-0982.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1199">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:4.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:6.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:7.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:adobe:acrobat_reader:8.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:acrobat_reader:4.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:4.0.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:4.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:5.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:5.0.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:5.0.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:5.0.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:5.0.9</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:5.0.10</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:5.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:6.0.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.1</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.2</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.3</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.4</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.5</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.6</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.7</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.8</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:7.0.9</vuln:product>
      <vuln:product>cpe:/a:adobe:acrobat_reader:8.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1199</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:40.360-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200803-01.xml" xml:lang="en">GLSA-200803-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.gnucitizen.org/projects/pdf-strikes-back/" xml:lang="en">http://www.gnucitizen.org/projects/pdf-strikes-back/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22753" xml:lang="en">22753</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32815" xml:lang="en">adobe-pdf-file-information-disclosure(32815)</vuln:reference>
    </vuln:references>
    <vuln:summary>Adobe Reader and Acrobat Trial allow remote attackers to read arbitrary files via a file:// URI in a PDF document, as demonstrated with &lt;&lt;/URI(file:///C:/)/S/URI>>, a different issue than CVE-2007-0045.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1201">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:biztalk_server:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:biztalk_server:2002"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:commerce_server:2000"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_security_and_acceleration_server:2000:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:xp:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visual_studio_.net:2002:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visual_studio_.net:2003:sp1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:biztalk_server:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:biztalk_server:2002</vuln:product>
      <vuln:product>cpe:/a:microsoft:commerce_server:2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_security_and_acceleration_server:2000:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:xp:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:visual_studio_.net:2002:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:visual_studio_.net:2003:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1201</vuln:cve-id>
    <vuln:published-datetime>2008-03-11T19:44:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-12T17:43:04.157-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5327" name="oval:org.mitre.oval:def:5327"/>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" xml:lang="en">SSRT080028</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/28136" xml:lang="en">28136</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1019581" xml:lang="en">1019581</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA08-071A.html" xml:lang="en">TA08-071A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2008/0849/references" xml:lang="en">ADV-2008-0849</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-017" xml:lang="en">MS08-017</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in certain COM objects in Microsoft Office Web Components 2000 allows user-assisted remote attackers to execute arbitrary code via vectors related to DataSource that trigger memory corruption, aka "Office Web Components DataSource Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2007-1202">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2002:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:2004::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word_viewer:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2004"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2005"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:works:2006"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:word:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2002:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:2004::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:word_viewer:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2004</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2005</vuln:product>
      <vuln:product>cpe:/a:microsoft:works:2006</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1202</vuln:cve-id>
    <vuln:published-datetime>2007-05-08T19:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:03.487-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1900" name="oval:org.mitre.oval:def:1900"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=525" xml:lang="en">20070508 Microsoft Word RTF File Parsing Heap Corruption Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/555489" xml:lang="en">VU#555489</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/468871/100/200/threaded" xml:lang="en">HPSBST02214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23836" xml:lang="en">23836</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018013" xml:lang="en">1018013</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" xml:lang="en">TA07-128A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1709" xml:lang="en">ADV-2007-1709</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-024" xml:lang="en">MS07-024</vuln:reference>
    </vuln:references>
    <vuln:summary>Word (or Word Viewer) in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, 2004 for Mac, and Works Suite 2004, 2005, and 2006 does not properly parse certain rich text "property strings of certain control words," which allows user-assisted remote attackers to trigger heap corruption and execute arbitrary code, aka the "Word RTF Parsing Vulnerability."</vuln:summary>
  </entry>
  <entry id="CVE-2007-1203">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2002:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2004::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2007"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel_viewer:2003"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:excel:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2002:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2004::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2007</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel_viewer:2003</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1203</vuln:cve-id>
    <vuln:published-datetime>2007-05-08T18:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:04.220-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2014" name="oval:org.mitre.oval:def:2014"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/468871/100/200/threaded" xml:lang="en">HPSBST02214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23779" xml:lang="en">23779</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018012" xml:lang="en">1018012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" xml:lang="en">TA07-128A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1708" xml:lang="en">ADV-2007-1708</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-023" xml:lang="en">MS07-023</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33914" xml:lang="en">excel-placeholder-code-execution(33914)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, 2004 for Mac, and 2007 allows user-assisted remote attackers to execute arbitrary code via a crafted set font value in an Excel file, which results in memory corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1204">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1204</vuln:cve-id>
    <vuln:published-datetime>2007-04-10T17:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:04.987-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>ADJACENT_NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2049" name="oval:org.mitre.oval:def:2049"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=509" xml:lang="en">20070410 Microsoft Windows Universal Plug and Play Memory Corruption Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/466331/100/200/threaded" xml:lang="en">HPSBST02208</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23371" xml:lang="en">23371</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017895" xml:lang="en">1017895</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1323" xml:lang="en">ADV-2007-1323</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-019" xml:lang="en">MS07-019</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in the Universal Plug and Play (UPnP) service in Microsoft Windows XP SP2 allows remote attackers on the same subnet to execute arbitrary code via crafted HTTP headers in request or notification messages, which trigger memory corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1205">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:gold::itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1::itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp2::itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp2::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional_x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:gold::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp1::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp1::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp2::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp2::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional_x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:professional_x64</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1205</vuln:cve-id>
    <vuln:published-datetime>2007-04-10T17:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:05.627-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2034" name="oval:org.mitre.oval:def:2034"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/728057" xml:lang="en">VU#728057</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/465235/100/0/threaded" xml:lang="en">20070410 Secunia Research: Microsoft Agent URL Parsing Memory CorruptionVulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/466331/100/200/threaded" xml:lang="en">HPSBST02208</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23337" xml:lang="en">23337</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017896" xml:lang="en">1017896</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-100A.html" xml:lang="en">TA07-100A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1324" xml:lang="en">ADV-2007-1324</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-020" xml:lang="en">MS07-020</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Microsoft Agent (msagent\agentsvr.exe) in Windows 2000 SP4, XP SP2, and Server 2003, 2003 SP1, and 2003 SP2 allows remote attackers to execute arbitrary code via crafted URLs, which result in memory corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1206">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1206</vuln:cve-id>
    <vuln:published-datetime>2007-04-10T17:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:06.470-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1639" name="oval:org.mitre.oval:def:1639"/>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://research.eeye.com/html/advisories/published/AD20070410a.html" xml:lang="en">http://research.eeye.com/html/advisories/published/AD20070410a.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017898" xml:lang="en">1017898</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/337953" xml:lang="en">VU#337953</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/465232/100/0/threaded" xml:lang="en">20070410 EEYE: Windows VDM Zero Page Race Condition Privilege Escalation</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/466331/100/200/threaded" xml:lang="en">HPSBST02208</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23367" xml:lang="en">23367</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-100A.html" xml:lang="en">TA07-100A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1326" xml:lang="en">ADV-2007-1326</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-022" xml:lang="en">MS07-022</vuln:reference>
    </vuln:references>
    <vuln:summary>The Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4.0; 2000 SP4; XP SP2; Server 2003, 2003 SP1, and 2003 SP2; and Windows Vista before June 2006; uses insecure permissions (PAGE_READWRITE) for a physical memory view, which allows local users to gain privileges by modifying the "zero page" during a race condition before the view is unmapped.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1207">
    <vuln:cve-id>CVE-2007-1207</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:05.777-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:05.793-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2007. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1208">
    <vuln:cve-id>CVE-2007-1208</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:05.807-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:05.807-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2007. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1209">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_vista</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1209</vuln:cve-id>
    <vuln:published-datetime>2007-04-10T17:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:07.423-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1524" name="oval:org.mitre.oval:def:1524"/>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://research.eeye.com/html/advisories/published/AD20070410b.html" xml:lang="en">http://research.eeye.com/html/advisories/published/AD20070410b.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2531" xml:lang="en">2531</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/219848" xml:lang="en">VU#219848</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/465233/100/0/threaded" xml:lang="en">20070410 EEYE: Windows Vista CSRSS Dangling Process Pointer Privilege Escalation</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/466331/100/200/threaded" xml:lang="en">HPSBST02208</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23338" xml:lang="en">23338</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017897" xml:lang="en">1017897</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-100A.html" xml:lang="en">TA07-100A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1325" xml:lang="en">ADV-2007-1325</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-021" xml:lang="en">MS07-021</vuln:reference>
    </vuln:references>
    <vuln:summary>Use-after-free vulnerability in the Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows Vista does not properly handle connection resources when starting and stopping processes, which allows local users to gain privileges by opening and closing multiple ApiPort connections, which leaves a "dangling pointer" to a process data structure.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1210">
    <vuln:cve-id>CVE-2007-1210</vuln:cve-id>
    <vuln:published-datetime>2017-05-11T10:29:05.840-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-05-11T10:29:05.840-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2007. Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1211">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:gold::itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:gold::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1::itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp2::itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp2::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional_x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:gold::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:gold::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp1::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp2::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp2::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional_x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:professional_x64</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1211</vuln:cve-id>
    <vuln:published-datetime>2007-04-04T12:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:08.487-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1571" name="oval:org.mitre.oval:def:1571"/>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=499" xml:lang="en">20070403 Microsoft Windows WMF Triggerable Kernel Design Error DoS Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/466186/100/200/threaded" xml:lang="en">HPSBST02206</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23275" xml:lang="en">23275</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017843" xml:lang="en">1017843</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1215" xml:lang="en">ADV-2007-1215</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-017" xml:lang="en">MS07-017</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33258" xml:lang="en">win-wmf-dos(33258)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified kernel GDI functions in Microsoft Windows 2000 SP4; XP SP2; and Server 2003 Gold, SP1, and SP2 allows user-assisted remote attackers to cause a denial of service (possibly persistent restart) via a crafted Windows Metafile (WMF) image that causes an invalid dereference of an offset in a kernel structure, a related issue to CVE-2005-4560.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1212">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:gold::itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:gold::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1::itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp2::itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp2::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::gold:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional_x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:gold::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:gold::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp1::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp2::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp2::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::gold:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional_x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:professional_x64</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1212</vuln:cve-id>
    <vuln:published-datetime>2007-04-04T12:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:09.157-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1923" name="oval:org.mitre.oval:def:1923"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/466186/100/200/threaded" xml:lang="en">HPSBST02206</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23278" xml:lang="en">23278</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017844" xml:lang="en">1017844</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1215" xml:lang="en">ADV-2007-1215</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-017" xml:lang="en">MS07-017</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4; XP SP2; Server 2003 Gold, SP1, and SP2; and Vista allows local users to gain privileges via a crafted Enhanced Metafile (EMF) image format file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1213">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1213</vuln:cve-id>
    <vuln:published-datetime>2007-04-04T12:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:09.673-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1797" name="oval:org.mitre.oval:def:1797"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/466186/100/200/threaded" xml:lang="en">HPSBST02206</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23276" xml:lang="en">23276</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017845" xml:lang="en">1017845</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1215" xml:lang="en">ADV-2007-1215</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-017" xml:lang="en">MS07-017</vuln:reference>
    </vuln:references>
    <vuln:summary>The TrueType Fonts rasterizer in Microsoft Windows 2000 SP4 allows local users to gain privileges via crafted TrueType fonts, which result in an uninitialized function pointer.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1214">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2000:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2002:sp3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2003:sp2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2004::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel_viewer:2003"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:excel:2000:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2002:sp3</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2003:sp2</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2004::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel_viewer:2003</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1214</vuln:cve-id>
    <vuln:published-datetime>2007-05-08T18:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:10.127-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2064" name="oval:org.mitre.oval:def:2064"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=527" xml:lang="en">20070508 Microsoft Excel Filter Record Code Execution Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/253825" xml:lang="en">VU#253825</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/468871/100/200/threaded" xml:lang="en">HPSBST02214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23780" xml:lang="en">23780</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018012" xml:lang="en">1018012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" xml:lang="en">TA07-128A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1708" xml:lang="en">ADV-2007-1708</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-023" xml:lang="en">MS07-023</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33915" xml:lang="en">excel-autofilter-code-execution(33915)</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, and 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a crafted AutoFilter filter record in an Excel BIFF8 format XLS file, which triggers memory corruption.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1215">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:gold::itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:gold::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp1::itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp2::itanium"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2003_server:sp2::x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_vista::gold:x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::gold:professional_x64"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2:professional_x64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000::sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:gold::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:gold::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp1::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp2::itanium</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2003_server:sp2::x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_vista::gold:x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::gold:professional_x64</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_xp::sp2:professional_x64</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1215</vuln:cve-id>
    <vuln:published-datetime>2007-04-04T12:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:11.033-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1927" name="oval:org.mitre.oval:def:1927"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/466186/100/200/threaded" xml:lang="en">HPSBST02206</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23273" xml:lang="en">23273</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017847" xml:lang="en">1017847</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1215" xml:lang="en">ADV-2007-1215</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-017" xml:lang="en">MS07-017</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4; XP SP2; Server 2003 Gold, SP1, and SP2; and Vista allows local users to gain privileges via certain "color-related parameters" in crafted images.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1216">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5-1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mit:kerberos:5-1.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1216</vuln:cve-id>
    <vuln:published-datetime>2007-04-05T21:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:11.533-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>8.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11135" name="oval:org.mitre.oval:def:11135"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070401-01-P.asc" xml:lang="en">20070401-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305391" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305391</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01056923" xml:lang="en">HPSBUX02217</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" xml:lang="en">APPLE-SA-2007-04-19</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Apr/0001.html" xml:lang="en">SUSE-SA:2007:025</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200704-02.xml" xml:lang="en">GLSA-200704-02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2007-003.txt" xml:lang="en">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2007-003.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1276" xml:lang="en">DSA-1276</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/419344" xml:lang="en">VU#419344</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:077" xml:lang="en">MDKSA-2007:077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0095.html" xml:lang="en">RHSA-2007:0095</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/464591/100/0/threaded" xml:lang="en">20070403 MITKRB5-SA-2007-003: double-free vulnerability in kadmind (via GSS-API library) [CVE-2007-1216]</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/464666/100/0/threaded" xml:lang="en">20070404 rPSA-2007-0063-1 krb5 krb5-server krb5-services krb5-test krb5-workstation</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/464814/30/7170/threaded" xml:lang="en">20070405 FLEA-2007-0008-1: krb5</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23282" xml:lang="en">23282</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017852" xml:lang="en">1017852</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-449-1" xml:lang="en">USN-449-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-093B.html" xml:lang="en">TA07-093B</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" xml:lang="en">TA07-109A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1218" xml:lang="en">ADV-2007-1218</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1470" xml:lang="en">ADV-2007-1470</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1916" xml:lang="en">ADV-2007-1916</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33413" xml:lang="en">kerberos-kadmind-code-execution(33413)</vuln:reference>
    </vuln:references>
    <vuln:summary>Double free vulnerability in the GSS-API library (lib/gssapi/krb5/k5unseal.c), as used by the Kerberos administration daemon (kadmind) in MIT krb5 before 1.6.1, when used with the authentication method provided by the RPCSEC_GSS RPC library, allows remote authenticated users to execute arbitrary code and modify the Kerberos key database via a message with an "an invalid direction encoding".</vuln:summary>
  </entry>
  <entry id="CVE-2007-1217">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.10:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.10:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.10:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11::x86_64"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.11_rc1_bk6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.12.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13:rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.13.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.14.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15:rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.15.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.21"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.22"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.23"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.24"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.25"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.26"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.27"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.28"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.29"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.30"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.31"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.32"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.33"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.34"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.35"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.36"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.37"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.38"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.39"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.40"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16.41"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.16_rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.8"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.9"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.11"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.17.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18:rc7"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.5"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.18.6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19:rc1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19:rc2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19:rc3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19:rc4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.19.3"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.10:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.10:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.10:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11::x86_64</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.11_rc1_bk6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.12.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13:rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.13.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.14.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15:rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.15.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.21</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.22</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.23</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.24</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.25</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.26</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.27</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.28</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.29</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.30</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.31</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.32</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.33</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.34</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.35</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.36</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.37</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.38</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.39</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.40</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16.41</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.16_rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.9</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.11</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.17.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18:rc7</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.5</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.18.6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19:rc1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19:rc2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19:rc3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19:rc4</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.2</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.19.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1217</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:10.013-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10503" name="oval:org.mitre.oval:def:10503"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=408530" xml:lang="en">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=408530</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://bugzilla.kernel.org/show_bug.cgi?id=8028" xml:lang="en">http://bugzilla.kernel.org/show_bug.cgi?id=8028</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200704-23.xml" xml:lang="en">GLSA-200704-23</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2007-404.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2007-404.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:078" xml:lang="en">MDKSA-2007:078</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0671.html" xml:lang="en">RHSA-2007:0671</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0672.html" xml:lang="en">RHSA-2007:0672</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0673.html" xml:lang="en">RHSA-2007:0673</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0705.html" xml:lang="en">RHSA-2007:0705</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0774.html" xml:lang="en">RHSA-2007:0774</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23333" xml:lang="en">23333</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018539" xml:lang="en">1018539</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the bufprint function in capiutil.c in libcapi, as used in Linux kernel 2.6.9 to 2.6.20 and isdn4k-utils, allows local users to cause a denial of service (crash) and possibly gain privileges via a crafted CAPI packet.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1218">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:tcpdump:tcpdump:3.9.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:tcpdump:tcpdump:3.9.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1218</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T16:18:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:47.720-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9520" name="oval:org.mitre.oval:def:9520"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://cvs.tcpdump.org/cgi-bin/cvsweb/tcpdump/print-802_11.c" xml:lang="en">http://cvs.tcpdump.org/cgi-bin/cvsweb/tcpdump/print-802_11.c</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://cvs.tcpdump.org/cgi-bin/cvsweb/tcpdump/print-802_11.c?r1=1.31.2.11&amp;r2=1.31.2.12" xml:lang="en">http://cvs.tcpdump.org/cgi-bin/cvsweb/tcpdump/print-802_11.c?r1=1.31.2.11&amp;r2=1.31.2.12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=307179" xml:lang="en">http://docs.info.apple.com/article.html?artnum=307179</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2798" xml:lang="en">FEDORA-2007-347</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2799" xml:lang="en">FEDORA-2007-348</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.html" xml:lang="en">APPLE-SA-2007-12-17</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://seclists.org/fulldisclosure/2007/Mar/0003.html" xml:lang="en">20070301 tcpdump: off-by-one heap overflow in 802.11 printer</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1272" xml:lang="en">DSA-1272</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:056" xml:lang="en">MDKSA-2007:056</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:155" xml:lang="en">MDKSA-2007:155</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0368.html" xml:lang="en">RHSA-2007:0368</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0387.html" xml:lang="en">RHSA-2007:0387</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22772" xml:lang="en">22772</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017717" xml:lang="en">1017717</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TURBO</vuln:source>
      <vuln:reference href="http://www.turbolinux.com/security/2007/TLSA-2007-46.txt" xml:lang="en">TLSA-2007-46</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-429-1" xml:lang="en">USN-429-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.us-cert.gov/cas/techalerts/TA07-352A.html" xml:lang="en">TA07-352A</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0793" xml:lang="en">ADV-2007-0793</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/4238" xml:lang="en">ADV-2007-4238</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugs.gentoo.org/show_bug.cgi?id=168916" xml:lang="en">https://bugs.gentoo.org/show_bug.cgi?id=168916</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32749" xml:lang="en">tcpdump-print80211c-bo(32749)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1100" xml:lang="en">https://issues.rpath.com/browse/RPL-1100</vuln:reference>
    </vuln:references>
    <vuln:summary>Off-by-one buffer overflow in the parse_elements function in the 802.11 printer code (print-802_11.c) for tcpdump 3.9.5 and earlier allows remote attackers to cause a denial of service (crash) via a crafted 802.11 frame.  NOTE: this was originally referred to as heap-based, but it might be stack-based.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1219">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:admin_phorum:admin_phorum:3.3.1a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:admin_phorum:admin_phorum:3.3.1a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1219</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T17:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:47.783-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22739" xml:lang="en">22739</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0778" xml:lang="en">ADV-2007-0778</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32719" xml:lang="en">admin-phorum-del-file-include(32719)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3382" xml:lang="en">3382</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in actions/del.php in Admin Phorum 3.3.1a allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1220">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/h:microsoft:xbox_360:4532"/>
          <cpe-lang:fact-ref name="cpe:/h:microsoft:xbox_360:4548"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/h:microsoft:xbox_360"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:microsoft:xbox_360:4532</vuln:product>
      <vuln:product>cpe:/h:microsoft:xbox_360:4548</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1220</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T17:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:17.640-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2367" xml:lang="en">2367</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461489/100/0/threaded" xml:lang="en">20070227 Xbox 360 Hypervisor Privilege Escalation Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22745" xml:lang="en">22745</vuln:reference>
    </vuln:references>
    <vuln:summary>The Hypervisor in Microsoft Xbox 360 kernel 4532 and 4548 does not properly verify the parameters passed to the syscall dispatcher, which allows attackers with physical access to bypass code-signing requirements and execute arbitrary code.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1221">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:microsoft:xbox_360:4532"/>
        <cpe-lang:fact-ref name="cpe:/h:microsoft:xbox_360:4548"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:microsoft:xbox_360:4532</vuln:product>
      <vuln:product>cpe:/h:microsoft:xbox_360:4548</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1221</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T17:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:18.657-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2367" xml:lang="en">2367</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461489/100/0/threaded" xml:lang="en">20070227 Xbox 360 Hypervisor Privilege Escalation Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/463974/100/200/threaded" xml:lang="en">20070327 Re: RE: Xbox 360 Hypervisor Privilege Escalation Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22745" xml:lang="en">22745</vuln:reference>
    </vuln:references>
    <vuln:summary>The Hypervisor in Microsoft Xbox 360 kernel 4532 and 4548 allows attackers with physical access to force execution of the hypervisor syscall with a certain register set, which bypasses intended code protection.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1222">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x:10.4.9"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:parallels:parallels_desktop"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:parallels:parallels_desktop</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1222</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T17:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-15T01:43:49.187-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.immunitysec.com/pipermail/dailydave/2007-February/004091.html" xml:lang="en">[dailydave] 20070216 Minor Virtualization Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:summary>Parallels Desktop for Mac before 20070216 implements Drag and Drop by sharing the entire host filesystem as the .psf share, which allows local users of the guest operating system to write arbitrary files to the host filesystem, and execute arbitrary code via launchd by writing a plist file to a LaunchAgents directory.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1223">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:hitachi:osas%2fft%2fw:01-10"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:osas%2fft%2fw:01-10-%2fa"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:ibm:aix"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:hitachi:osas%2fft%2fw:01-00"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:osas%2fft%2fw:01-01"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:osas%2fft%2fw:01-02"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:osas%2fft%2fw:01-03"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:osas%2fft%2fw:01-04"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:osas%2fft%2fw:01-05"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:osas%2fft%2fw:01-06"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:osas%2fft%2fw:01-07"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:osas%2fft%2fw:01-08"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:osas%2fft%2fw:01-09"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:osas%2fft%2fw:01-10"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:hitachi:hi-ux%2fwe2"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:hitachi:osas%2fft%2fw:01-00"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:osas%2fft%2fw:01-01"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:osas%2fft%2fw:01-02"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:osas%2fft%2fw:01-03"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:osas%2fft%2fw:01-04"/>
          <cpe-lang:fact-ref name="cpe:/a:hitachi:osas%2fft%2fw:01-05"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:sun:solaris"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hitachi:osas%2fft%2fw:01-00</vuln:product>
      <vuln:product>cpe:/a:hitachi:osas%2fft%2fw:01-01</vuln:product>
      <vuln:product>cpe:/a:hitachi:osas%2fft%2fw:01-02</vuln:product>
      <vuln:product>cpe:/a:hitachi:osas%2fft%2fw:01-03</vuln:product>
      <vuln:product>cpe:/a:hitachi:osas%2fft%2fw:01-04</vuln:product>
      <vuln:product>cpe:/a:hitachi:osas%2fft%2fw:01-05</vuln:product>
      <vuln:product>cpe:/a:hitachi:osas%2fft%2fw:01-06</vuln:product>
      <vuln:product>cpe:/a:hitachi:osas%2fft%2fw:01-07</vuln:product>
      <vuln:product>cpe:/a:hitachi:osas%2fft%2fw:01-08</vuln:product>
      <vuln:product>cpe:/a:hitachi:osas%2fft%2fw:01-09</vuln:product>
      <vuln:product>cpe:/a:hitachi:osas%2fft%2fw:01-10</vuln:product>
      <vuln:product>cpe:/a:hitachi:osas%2fft%2fw:01-10-%2fa</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1223</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T17:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:40.843-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.hitachi-support.com/security_e/vuls_e/HS07-004_e/index-e.html" xml:lang="en">http://www.hitachi-support.com/security_e/vuls_e/HS07-004_e/index-e.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32696" xml:lang="en">osas-unspecified-dos(32696)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Hitachi OSAS/FT/W before 20070223 allows attackers to cause a denial of service (responder control processing halt) by sending "data unexpectedly through the port".</vuln:summary>
  </entry>
  <entry id="CVE-2007-1224">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:grok_developments:netproxy:4.03"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:grok_developments:netproxy:4.03</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1224</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T17:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:47.847-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22741" xml:lang="en">22741</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0779" xml:lang="en">ADV-2007-0779</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32697" xml:lang="en">netproxy-url-filtering-bypass(32697)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3381" xml:lang="en">3381</vuln:reference>
    </vuln:references>
    <vuln:summary>Grok Developments NetProxy 4.03 allows remote attackers to bypass URL filtering via a request that omits "http://" from the URL and specifies the destination port (:80).</vuln:summary>
  </entry>
  <entry id="CVE-2007-1225">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:grok_developments:netproxy:4.03"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:grok_developments:netproxy:4.03</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1225</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T17:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:47.907-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22741" xml:lang="en">22741</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0779" xml:lang="en">ADV-2007-0779</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32697" xml:lang="en">netproxy-url-filtering-bypass(32697)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3381" xml:lang="en">3381</vuln:reference>
    </vuln:references>
    <vuln:summary>The connection log file implementation in Grok Developments NetProxy 4.03 does not record requests that omit http:// in a URL, which might allow remote attackers to conduct unauthorized activities and avoid detection.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1226">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mcafee:virex:7.7::macintosh"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mcafee:virex:7.7::macintosh</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1226</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T17:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:20.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2342" xml:lang="en">2342</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461485/100/0/threaded" xml:lang="en">20070227 [NETRAGARD-20070220 SECURITY ADVISORY] [McAfee VirusScan for Mac (Virex) Local root exploit and Scan Bypass]</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22744" xml:lang="en">22744</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017707" xml:lang="en">1017707</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0777" xml:lang="en">ADV-2007-0777</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://knowledge.mcafee.com/SupportSite/dynamickc.do?externalId=518722&amp;sliceId=SAL_Public&amp;command=show&amp;forward=nonthreadedKC&amp;kcId=518722" xml:lang="en">https://knowledge.mcafee.com/SupportSite/dynamickc.do?externalId=518722&amp;sliceId=SAL_Public&amp;command=show&amp;forward=nonthreadedKC&amp;kcId=518722</vuln:reference>
    </vuln:references>
    <vuln:summary>McAfee VirusScan for Mac (Virex) before 7.7 patch 1 has weak permissions (0666) for /Library/Application Support/Virex/VShieldExclude.txt, which allows local users to reconfigure Virex to skip scanning of arbitrary files.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1227">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mcafee:virex:6.2:-:mac"/>
        <cpe-lang:fact-ref name="cpe:/a:mcafee:virex:7.7:-:mac"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mcafee:virex:6.2:-:mac</vuln:product>
      <vuln:product>cpe:/a:mcafee:virex:7.7:-:mac</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1227</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T17:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:22.267-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2342" xml:lang="en">2342</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461485/100/0/threaded" xml:lang="en">20070227 [NETRAGARD-20070220 SECURITY ADVISORY] [McAfee VirusScan for Mac (Virex) Local root exploit and Scan Bypass]</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22744" xml:lang="en">22744</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017707" xml:lang="en">1017707</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0777" xml:lang="en">ADV-2007-0777</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32729" xml:lang="en">mcafee-virex-library-privilege-escalation(32729)</vuln:reference>
    </vuln:references>
    <vuln:summary>VShieldCheck in McAfee VirusScan for Mac (Virex) before 7.7 patch 1 allow local users to change permissions of arbitrary files via a symlink attack on /Library/Application Support/Virex/VShieldExclude.txt, as demonstrated by symlinking to the root crontab file to execute arbitrary commands.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1228">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.2"/>
          <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.2:fp1"/>
          <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.2:fp2"/>
          <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.2:fp3"/>
          <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.2:fp4"/>
          <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.2:fp5"/>
          <cpe-lang:fact-ref name="cpe:/a:ibm:db2:8.2:fp6"/>
          <cpe-lang:fact-ref name="cpe:/a:ibm:db2:9.0"/>
          <cpe-lang:fact-ref name="cpe:/a:ibm:db2:9.0:fp1"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:unix:unix"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:db2:8.2</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:8.2:fp1</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:8.2:fp2</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:8.2:fp3</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:8.2:fp4</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:8.2:fp5</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:8.2:fp6</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:9.0</vuln:product>
      <vuln:product>cpe:/a:ibm:db2:9.0:fp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1228</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T17:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-02-11T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.4</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-03-06T15:01:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-287"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22729" xml:lang="en">22729</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017731" xml:lang="en">1017731</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?uid=swg1IY86711" xml:lang="en">IY86711</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/docview.wss?uid=swg1IY87492" xml:lang="en">IY87492</vuln:reference>
    </vuln:references>
    <vuln:summary>IBM DB2 UDB 8.2 before Fixpak 7 (aka fixpack 14), and DB2 9 before Fix Pack 2, on UNIX allows the "fenced" user to access certain unauthorized directories.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1229">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:nullsoft:shoutcast_server:1.9.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:nullsoft:shoutcast_server:1.9.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1229</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T17:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:25.063-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0604.html" xml:lang="en">20070227 Nullsoft ShoutcastServer Persistant XSS - 0day</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461474/100/0/threaded" xml:lang="en">20070227 Nullsoft ShoutcastServer Persistant XSS - 0day</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22742" xml:lang="en">22742</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0775" xml:lang="en">ADV-2007-0775</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32726" xml:lang="en">shoutcast-admin-interface-xss(32726)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in the Nullsoft ShoutcastServer 1.9.7 allows remote attackers to inject arbitrary web script or HTML via the top-level URI on the Incoming interface (port 8001/tcp), which is not properly handled in the administrator interface when viewing the log file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1230">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wordpress:wordpress:2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1230</vuln:cve-id>
    <vuln:published-datetime>2007-03-02T17:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:51:33.377-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://trac.wordpress.org/changeset/4951" xml:lang="en">http://trac.wordpress.org/changeset/4951</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://trac.wordpress.org/changeset/4952" xml:lang="en">http://trac.wordpress.org/changeset/4952</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200703-23.xml" xml:lang="en">GLSA-200703-23</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0756" xml:lang="en">ADV-2007-0756</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/functions.php in WordPress before 2.1.2-alpha allow remote attackers to inject arbitrary web script or HTML via (1) the Referer HTTP header or (2) the URI, a different vulnerability than CVE-2007-1049.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1231">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sqlitemanager:sqlitemanager:1.2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sqlitemanager:sqlitemanager:1.2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1231</vuln:cve-id>
    <vuln:published-datetime>2007-03-03T14:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:27.453-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2366" xml:lang="en">2366</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461304/100/0/threaded" xml:lang="en">20070224 SQLiteManager v1.2.0 Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22731" xml:lang="en">22731</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32692" xml:lang="en">sqlitemanager-main-xss(32692)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in SQLiteManager 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) database name, (2) table name, (3) ViewName, (4) view, (5) trigger, and (6) function fields in main.php and certain other files.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1232">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sqlite_manager:sqlite_manager:1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sqlite_manager:sqlite_manager:1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1232</vuln:cve-id>
    <vuln:published-datetime>2007-03-03T14:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:28.047-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2366" xml:lang="en">2366</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461304/100/0/threaded" xml:lang="en">20070224 SQLiteManager v1.2.0 Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22727" xml:lang="en">22727</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32693" xml:lang="en">sqlitemanager-sqlitemanager-file-include(32693)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in SQLiteManager 1.2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in a SQLiteManager_currentTheme cookie.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1233">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:1.11"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:1.21"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:1.22"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:2.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:2.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:2.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:2.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:2.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:2.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:2.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:2.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:2.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:2.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:2.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:2.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:2.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:2.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:2.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:2.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:2.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:2.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:2.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:2.6.5"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:2.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:2.7.0"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:2.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:2.8.0"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:2.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:2.9.0"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:2.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:3.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:3.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:3.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:3.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:stwc-counter:stwc-counter:3.4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:1.1</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:1.2</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:1.11</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:1.12</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:1.21</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:1.22</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:2.0.0</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:2.0.1</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:2.0.2</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:2.1.0</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:2.1.1</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:2.2.0</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:2.2.1</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:2.2.2</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:2.2.3</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:2.2.4</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:2.2.5</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:2.2.6</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:2.2.7</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:2.3.0</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:2.3.1</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:2.4.0</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:2.5.0</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:2.5.1</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:2.5.2</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:2.6.0</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:2.6.1</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:2.6.2</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:2.6.3</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:2.6.4</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:2.6.5</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:2.6.6</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:2.7.0</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:2.7.1</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:2.8.0</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:2.8.1</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:2.9.0</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:2.9.1</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:3.0.0</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:3.0.1</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:3.0.2</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:3.0.3</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:3.1.0</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:3.2.0</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:3.3.0</vuln:product>
      <vuln:product>cpe:/a:stwc-counter:stwc-counter:3.4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1233</vuln:cve-id>
    <vuln:published-datetime>2007-03-03T14:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:47.970-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22723" xml:lang="en">22723</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0754" xml:lang="en">ADV-2007-0754</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32681" xml:lang="en">stwccounter-downloadcounter-file-include(32681)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3379" xml:lang="en">3379</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in downloadcounter.php in STWC-Counter 3.4.0.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the stwc_counter_verzeichniss parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1234">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bj_sintay:sitex:0.7.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bj_sintay:sitex:0.7.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1234</vuln:cve-id>
    <vuln:published-datetime>2007-03-03T14:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:28.470-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2373" xml:lang="en">2373</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461305/100/0/threaded" xml:lang="en">20070223 sitex multiple vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/465849/100/200/threaded" xml:lang="en">20070414 Re: sitex multiple vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in sitex allow remote attackers to inject arbitrary web script or HTML via (1) the sxYear parameter to calendar.php, (2) the search parameter to search.php, (3) the linkid parameter to redirect.php, or (4) the page parameter to calendar_events.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1235">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bj_sintay:sitex:0.7.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bj_sintay:sitex:0.7.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1235</vuln:cve-id>
    <vuln:published-datetime>2007-03-03T14:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:28.937-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2373" xml:lang="en">2373</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461305/100/0/threaded" xml:lang="en">20070223 sitex multiple vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:summary>Unrestricted file upload vulnerability in sitex allows remote attackers to upload arbitrary PHP code via an avatar filename with a double extension such as .php.jpg, which fails verification and is saved as a .php file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1236">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sitex:sitex"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sitex:sitex</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1236</vuln:cve-id>
    <vuln:published-datetime>2007-03-03T14:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:29.143-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2373" xml:lang="en">2373</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461305/100/0/threaded" xml:lang="en">20070223 sitex multiple vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:summary>sitex allows remote attackers to obtain sensitive information via a request with a numerical value for the (1) sxMonth[] or (2) sxYear[] parameter to calendar.php, or the (3) page[] parameter to calendar_events.php, which reveals the path in various error messages.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1237">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bj_sintay:sitex:0.7.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bj_sintay:sitex:0.7.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1237</vuln:cve-id>
    <vuln:published-datetime>2007-03-03T14:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:29.393-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2373" xml:lang="en">2373</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461305/100/0/threaded" xml:lang="en">20070223 sitex multiple vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:summary>sitex allows remote attackers to obtain potentially sensitive information via a ' (quote) value for certain parameters, as demonstrated by parameters used in forum and search, which forces a SQL error.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1238">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:2003"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:office:2003</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1238</vuln:cve-id>
    <vuln:published-datetime>2007-03-03T14:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:29.610-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://securityvulns.com/Qdocument120.html" xml:lang="en">http://securityvulns.com/Qdocument120.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461373/100/0/threaded" xml:lang="en">20070225 Few unreported vulnerabilities by SehaTo</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Office 2003 allows user-assisted remote attackers to cause a denial of service (application crash) by attempting to insert a corrupted WMF file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1239">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2003"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2003:sp1"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:excel:2003:sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:excel:2003</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2003:sp1</vuln:product>
      <vuln:product>cpe:/a:microsoft:excel:2003:sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1239</vuln:cve-id>
    <vuln:published-datetime>2007-03-03T14:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:29.813-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://securityvulns.com/news/Microsoft/Excel/XML/DoS.html" xml:lang="en">http://securityvulns.com/news/Microsoft/Excel/XML/DoS.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461373/100/0/threaded" xml:lang="en">20070225 Few unreported vulnerabilities by SehaTo</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22717" xml:lang="en">22717</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Excel 2003 does not properly parse .XLS files, which allows remote attackers to cause a denial of service (application crash) via a file with a (1) corrupted XML format or a (2) corrupted XLS format, which triggers a NULL pointer dereference.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1240">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:docebo:docebo:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:docebo:docebo:3.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:docebo:docebo:3.0.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:docebo:docebo:3.0.3</vuln:product>
      <vuln:product>cpe:/a:docebo:docebo:3.0.4</vuln:product>
      <vuln:product>cpe:/a:docebo:docebo:3.0.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1240</vuln:cve-id>
    <vuln:published-datetime>2007-03-03T14:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:41.377-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://downloads.securityfocus.com/vulnerabilities/exploits/22719.html" xml:lang="en">http://downloads.securityfocus.com/vulnerabilities/exploits/22719.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22719" xml:lang="en">22719</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32842" xml:lang="en">Docebocms-index-xss(32842)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Docebo CMS 3.0.3 through 3.0.5 allow remote attackers to inject arbitrary web script or HTML via (1) the searchkey parameter to index.php, or the (2) sn or (3) ri parameter to modules/htmlframechat/index.php.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1241">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:audins_audiens:audins_audiens:3.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:audins_audiens:audins_audiens:3.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1241</vuln:cve-id>
    <vuln:published-datetime>2007-03-03T14:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:41.453-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://downloads.securityfocus.com/vulnerabilities/exploits/22728.html" xml:lang="en">http://downloads.securityfocus.com/vulnerabilities/exploits/22728.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22728" xml:lang="en">22728</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32839" xml:lang="en">audins-setup-xss(32839)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in setup.php in Audins Audiens 3.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1242">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:audins_audiens:audins_audiens:3.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:audins_audiens:audins_audiens:3.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1242</vuln:cve-id>
    <vuln:published-datetime>2007-03-03T14:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:41.500-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22728" xml:lang="en">22728</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32837" xml:lang="en">audins-index-sql-injection(32837)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in system/index.php in Audins Audiens 3.3 allows remote attackers to execute arbitrary SQL commands via the PHPSESSID cookie.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1243">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:audins_audiens:audins_audiens:3.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:audins_audiens:audins_audiens:3.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1243</vuln:cve-id>
    <vuln:published-datetime>2007-03-03T14:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:41.547-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22728" xml:lang="en">22728</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32707" xml:lang="en">audins-unistall-authentication-bypass(32707)</vuln:reference>
    </vuln:references>
    <vuln:summary>Audins Audiens 3.3 allows remote attackers to bypass authentication and perform certain privileged actions, possibly an uninstall of the product, by calling unistall.php with the values cnf=disinstalla and status=on.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1244">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wordpress:wordpress:2.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1244</vuln:cve-id>
    <vuln:published-datetime>2007-03-03T14:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:30.017-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0583.html" xml:lang="en">20070226 WordPress AdminPanel CSRF/XSS - 0day</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200703-23.xml" xml:lang="en">GLSA-200703-23</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461351/100/0/threaded" xml:lang="en">20070226 WordPress AdminPanel CSRF/XSS - 0day</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22735" xml:lang="en">22735</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32703" xml:lang="en">wordpress-post-csrf(32703)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site request forgery (CSRF) vulnerability in the AdminPanel in WordPress 2.1.1 and earlier allows remote attackers to perform privileged actions as administrators, as demonstrated using the delete action in wp-admin/post.php.  NOTE: this issue can be leveraged to perform cross-site scripting (XSS) attacks and steal cookies via the post parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1245">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:irfanview:irfanview:3.99"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:irfanview:irfanview:3.99</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1245</vuln:cve-id>
    <vuln:published-datetime>2007-03-03T14:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:30.517-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://securityvulns.com/news/IrfanView/WMF/DoS.html" xml:lang="en">http://securityvulns.com/news/IrfanView/WMF/DoS.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://securityvulns.com/Qdocument120.html" xml:lang="en">http://securityvulns.com/Qdocument120.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461373/100/0/threaded" xml:lang="en">20070225 Few unreported vulnerabilities by SehaTo</vuln:reference>
    </vuln:references>
    <vuln:summary>IrfanView 3.99 allows remote attackers to cause a denial of service (application crash) via a malformed WMF file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1246">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mplayer:mplayer:1.0_rc1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mplayer:mplayer:1.0_rc1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1246</vuln:cve-id>
    <vuln:published-datetime>2007-03-03T14:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:30.783-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.6</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-March/052738.html" xml:lang="en">20070301 MPlayer DMO buffer overflow</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200704-09.xml" xml:lang="en">GLSA-200704-09</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200705-21.xml" xml:lang="en">GLSA-200705-21</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.449141" xml:lang="en">SSA:2007-109-02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://svn.mplayerhq.hu/mplayer/trunk/loader/dmo/DMO_VideoDecoder.c" xml:lang="en">http://svn.mplayerhq.hu/mplayer/trunk/loader/dmo/DMO_VideoDecoder.c</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://svn.mplayerhq.hu/mplayer/trunk/loader/dmo/DMO_VideoDecoder.c?r1=22019&amp;r2=22204" xml:lang="en">http://svn.mplayerhq.hu/mplayer/trunk/loader/dmo/DMO_VideoDecoder.c?r1=22019&amp;r2=22204</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2008/dsa-1536" xml:lang="en">DSA-1536</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:055" xml:lang="en">MDKSA-2007:055</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:057" xml:lang="en">MDKSA-2007:057</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_007_suse.html" xml:lang="en">SUSE-SR:2007:007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_5_sr.html" xml:lang="en">SUSE-SR:2007:005</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/466691/30/6900/threaded" xml:lang="en">20070423 FLEA-2007-0013-1: xine-lib</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22771" xml:lang="en">22771</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-433-1" xml:lang="en">USN-433-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0794" xml:lang="en">ADV-2007-0794</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32747" xml:lang="en">mplayer-dmovideodecoder-bo(32747)</vuln:reference>
    </vuln:references>
    <vuln:summary>The DMO_VideoDecoder_Open function in loader/dmo/DMO_VideoDecoder.c in MPlayer 1.0rc1 and earlier, as used in xine-lib, does not set the biSize before use in a memcpy, which allows user-assisted remote attackers to cause a buffer overflow and possibly execute arbitrary code, a different vulnerability than CVE-2007-1387.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1247">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:aweb_labs:awebnews:1.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:aweb_labs:awebnews:1.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1247</vuln:cve-id>
    <vuln:published-datetime>2007-03-03T15:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:35.643-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2365" xml:lang="en">2365</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461680/100/0/threaded" xml:lang="en">20070301 aWebNews v 1.1=>RFI</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461684/100/0/threaded" xml:lang="en">20070301 aWebNews V 1.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22781" xml:lang="en">22781</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0808" xml:lang="en">ADV-2007-0808</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32770" xml:lang="en">awebnews-pathtonews-file-include(32770)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple PHP remote file inclusion vulnerabilities in aWeb Labs aWebNews 1.5 allow remote attackers to execute arbitrary PHP code via a URL in the path_to_news parameter to (1) listing.php or (2) visview.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1248">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:built2go:news_manager_blog:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:built2go:news_manager_blog:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1248</vuln:cve-id>
    <vuln:published-datetime>2007-03-03T15:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:36.860-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2343" xml:lang="en">2343</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461672/100/0/threaded" xml:lang="en">20070301 Built2Go v.1.0 => ( news.php &amp; rating.php ) Cross Site Scripting</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22783" xml:lang="en">22783</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0818" xml:lang="en">ADV-2007-0818</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32772" xml:lang="en">newsmanagerblog-news-rating-xss(32772)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in built2go News Manager Blog 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) cid, (2) uid, and (3) nid parameters to (a) news.php, and the nid parameter to (b) rating.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1249">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:contelligent:c1_financial_services:9.1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:contelligent:c1_financial_services:9.1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1249</vuln:cve-id>
    <vuln:published-datetime>2007-03-03T15:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:41.860-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-362"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.contelligent.com/contell/cms/c1web/contelligent/site/contelligent/changelog.html?fromRelease=9.1.4" xml:lang="en">http://www.contelligent.com/contell/cms/c1web/contelligent/site/contelligent/changelog.html?fromRelease=9.1.4</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22785" xml:lang="en">22785</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0814" xml:lang="en">ADV-2007-0814</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32775" xml:lang="en">contelligent-sortedcontent-security-bypass(32775)</vuln:reference>
    </vuln:references>
    <vuln:summary>MoveSortedContentAction in C1 Financial Services Contelligent 9.1.4 does not check "the additional environment security configuration," which allows remote attackers with write permissions to reorder components.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1250">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:angel_learning:learning_management_suite:7.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:angel_learning:learning_management_suite:7.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1250</vuln:cve-id>
    <vuln:published-datetime>2007-03-03T15:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:37.143-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461638/100/0/threaded" xml:lang="en">20070301 Angel LMS 7.1 - Remote SQL Injection</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461673/100/0/threaded" xml:lang="en">20070301 Re: Angel LMS 7.1 - Remote SQL Injection</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461811/100/0/threaded" xml:lang="en">20070301 [Fwd: Re: Angel LMS 7.1 - Remote SQL Injection]</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22768" xml:lang="en">22768</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0807" xml:lang="en">ADV-2007-0807</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32756" xml:lang="en">angellms-default-sql-injection(32756)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3390" xml:lang="en">3390</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in section/default.asp in ANGEL Learning Management Suite (LMS) 7.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1251">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:netrek:netrek_vanilla_server:2.12.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:netrek:netrek_vanilla_server:2.12.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1251</vuln:cve-id>
    <vuln:published-datetime>2007-03-03T15:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:37.610-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-134"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://aluigi.altervista.org/adv/netrekfs-adv.txt" xml:lang="en">http://aluigi.altervista.org/adv/netrekfs-adv.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=490561" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=490561</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461755/100/0/threaded" xml:lang="en">20070302 Limited format string in Netrek 2.12.0</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22786" xml:lang="en">22786</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0815" xml:lang="en">ADV-2007-0815</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32777" xml:lang="en">vanilla-vsprintf-format-string(32777)</vuln:reference>
    </vuln:references>
    <vuln:summary>Format string vulnerability in the new_warning function in ntserv/warning.c for Netrek Vanilla Server 2.12.0, when EVENTLOG is enabled, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers in the message handling.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1252">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:symantec:mail_security:5.0::smtp"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:symantec:mail_security:5.0::smtp</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1252</vuln:cve-id>
    <vuln:published-datetime>2007-03-03T15:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:42.017-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="ftp://ftp.symantec.com/public/english_us_canada/products/symantec_mail_security/5.0_smtp/updates/release_notes_p175.txt" xml:lang="en">ftp://ftp.symantec.com/public/english_us_canada/products/symantec_mail_security/5.0_smtp/updates/release_notes_p175.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/875633" xml:lang="en">VU#875633</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22782" xml:lang="en">22782</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017716" xml:lang="en">1017716</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0799" xml:lang="en">ADV-2007-0799</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32781" xml:lang="en">symantec-email-headers-code-execution(32781)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Symantec Mail Security for SMTP 5.0 before Patch 175 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted headers in an e-mail message.  NOTE: some information was obtained from third party sources.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1253">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:blender:blender:2.25"/>
        <cpe-lang:fact-ref name="cpe:/a:blender:blender:2.36"/>
        <cpe-lang:fact-ref name="cpe:/a:blender:blender:2.37a"/>
        <cpe-lang:fact-ref name="cpe:/a:blender:blender:2.42a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:blender:blender:2.25</vuln:product>
      <vuln:product>cpe:/a:blender:blender:2.36</vuln:product>
      <vuln:product>cpe:/a:blender:blender:2.37a</vuln:product>
      <vuln:product>cpe:/a:blender:blender:2.42a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1253</vuln:cve-id>
    <vuln:published-datetime>2007-03-03T15:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:42.080-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-94"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200704-19.xml" xml:lang="en">GLSA-200704-19</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22770" xml:lang="en">22770</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017714" xml:lang="en">1017714</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0798" xml:lang="en">ADV-2007-0798</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32778" xml:lang="en">blender-kml-kmz-command-execution(32778)</vuln:reference>
    </vuln:references>
    <vuln:summary>Eval injection vulnerability in the (a) kmz_ImportWithMesh.py Script for Blender 0.1.9h, as used in (b) Blender before 2.43, allows user-assisted remote attackers to execute arbitrary Python code by importing a crafted (1) KML or (2) KMZ file.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1254">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:connectix:connectix_boards:0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:connectix:connectix_boards:0.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:connectix:connectix_boards:0.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:connectix:connectix_boards:0.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:connectix:connectix_boards:0.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:connectix:connectix_boards:0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:connectix:connectix_boards:0.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:connectix:connectix_boards:0.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:connectix:connectix_boards:0.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:connectix:connectix_boards:0.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:connectix:connectix_boards:0.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:connectix:connectix_boards:0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:connectix:connectix_boards:0.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:connectix:connectix_boards:0.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:connectix:connectix_boards:0.4</vuln:product>
      <vuln:product>cpe:/a:connectix:connectix_boards:0.4.1</vuln:product>
      <vuln:product>cpe:/a:connectix:connectix_boards:0.4.2</vuln:product>
      <vuln:product>cpe:/a:connectix:connectix_boards:0.4.3</vuln:product>
      <vuln:product>cpe:/a:connectix:connectix_boards:0.4.4</vuln:product>
      <vuln:product>cpe:/a:connectix:connectix_boards:0.5</vuln:product>
      <vuln:product>cpe:/a:connectix:connectix_boards:0.5.1</vuln:product>
      <vuln:product>cpe:/a:connectix:connectix_boards:0.5.2</vuln:product>
      <vuln:product>cpe:/a:connectix:connectix_boards:0.5.3</vuln:product>
      <vuln:product>cpe:/a:connectix:connectix_boards:0.5.4</vuln:product>
      <vuln:product>cpe:/a:connectix:connectix_boards:0.5.5</vuln:product>
      <vuln:product>cpe:/a:connectix:connectix_boards:0.6</vuln:product>
      <vuln:product>cpe:/a:connectix:connectix_boards:0.6.1</vuln:product>
      <vuln:product>cpe:/a:connectix:connectix_boards:0.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1254</vuln:cve-id>
    <vuln:published-datetime>2007-03-03T15:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:37.907-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2364" xml:lang="en">2364</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460947/100/0/threaded" xml:lang="en">20070221 Connectix Boards &lt;= 0.7 (p_skin) Multiple Vulnerabilities Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3352" xml:lang="en">3352</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in part.userprofile.php in Connectix Boards 0.7 and earlier allows remote authenticated users to execute arbitrary SQL commands and obtain privileges via the p_skin parameter to index.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1255">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:connectix:connectix_boards:0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:connectix:connectix_boards:0.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:connectix:connectix_boards:0.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:connectix:connectix_boards:0.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:connectix:connectix_boards:0.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:connectix:connectix_boards:0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:connectix:connectix_boards:0.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:connectix:connectix_boards:0.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:connectix:connectix_boards:0.5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:connectix:connectix_boards:0.5.4"/>
        <cpe-lang:fact-ref name="cpe:/a:connectix:connectix_boards:0.5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:connectix:connectix_boards:0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:connectix:connectix_boards:0.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:connectix:connectix_boards:0.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:connectix:connectix_boards:0.4</vuln:product>
      <vuln:product>cpe:/a:connectix:connectix_boards:0.4.1</vuln:product>
      <vuln:product>cpe:/a:connectix:connectix_boards:0.4.2</vuln:product>
      <vuln:product>cpe:/a:connectix:connectix_boards:0.4.3</vuln:product>
      <vuln:product>cpe:/a:connectix:connectix_boards:0.4.4</vuln:product>
      <vuln:product>cpe:/a:connectix:connectix_boards:0.5</vuln:product>
      <vuln:product>cpe:/a:connectix:connectix_boards:0.5.1</vuln:product>
      <vuln:product>cpe:/a:connectix:connectix_boards:0.5.2</vuln:product>
      <vuln:product>cpe:/a:connectix:connectix_boards:0.5.3</vuln:product>
      <vuln:product>cpe:/a:connectix:connectix_boards:0.5.4</vuln:product>
      <vuln:product>cpe:/a:connectix:connectix_boards:0.5.5</vuln:product>
      <vuln:product>cpe:/a:connectix:connectix_boards:0.6</vuln:product>
      <vuln:product>cpe:/a:connectix:connectix_boards:0.6.1</vuln:product>
      <vuln:product>cpe:/a:connectix:connectix_boards:0.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1255</vuln:cve-id>
    <vuln:published-datetime>2007-03-03T15:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:38.157-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2364" xml:lang="en">2364</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/460947/100/0/threaded" xml:lang="en">20070221 Connectix Boards &lt;= 0.7 (p_skin) Multiple Vulnerabilities Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3352" xml:lang="en">3352</vuln:reference>
    </vuln:references>
    <vuln:summary>Unrestricted file upload vulnerability in admin.bbcode.php in Connectix Boards 0.7 and earlier allows remote authenticated administrators to execute arbitrary PHP code by uploading a crafted GIF smiley image with a .php extension via the uploadimage parameter to admin.php, which can be later accessed via a direct request for the file in smileys/.  NOTE: this can be leveraged with a separate SQL injection issue for remote unauthenticated attacks.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1256">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:mozilla:firefox:2.0.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:firefox:2.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:firefox:2.0.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1256</vuln:cve-id>
    <vuln:published-datetime>2007-03-03T15:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:38.407-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://marc.info/?l=full-disclosure&amp;m=117258301222007&amp;w=2" xml:lang="en">20070227 Re: [Full-disclosure] Firefox onUnload + document.write() memory corruption vulnerability (MSIE7 null ptr)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://marc.info/?l=full-disclosure&amp;m=117259225402112&amp;w=2" xml:lang="en">20070227 RE: [Full-disclosure] Firefox onUnload + document.write() memory corruption vulnerability (MSIE7 null ptr)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461437/100/0/threaded" xml:lang="en">20070227 Re: [Full-disclosure] Firefox onUnload + document.write() memory corruption vulnerability (MSIE7 null ptr)</vuln:reference>
    </vuln:references>
    <vuln:summary>Mozilla Firefox 2.0.0.2 allows remote attackers to spoof the address bar, favicons, and document source, and perform updates in the context of arbitrary websites, by repeatedly setting document.location in the onunload attribute when linking to another website, a variant of CVE-2007-1092.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1257">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:cisco:network_analysis_module"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_6000_ws-svc-nam-1:2.2%281a%29"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_6000_ws-svc-nam-2:2.2%281a%29"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_6000_ws-x6380-nam:3.1%281a%29"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_6500_ws-svc-nam-1:2.2%281a%29"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_6500_ws-svc-nam-2:2.2%281a%29"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_6500_ws-x6380-nam:3.1%281a%29"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_7600_ws-svc-nam-1:2.2%281a%29"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_7600_ws-svc-nam-2:2.2%281a%29"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_7600_ws-x6380-nam:3.1%281a%29"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:cisco:catalyst_6000_ws-svc-nam-1:2.2%281a%29</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_6000_ws-svc-nam-2:2.2%281a%29</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_6000_ws-x6380-nam:3.1%281a%29</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_6500_ws-svc-nam-1:2.2%281a%29</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_6500_ws-svc-nam-2:2.2%281a%29</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_6500_ws-x6380-nam:3.1%281a%29</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_7600_ws-svc-nam-1:2.2%281a%29</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_7600_ws-svc-nam-2:2.2%281a%29</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_7600_ws-x6380-nam:3.1%281a%29</vuln:product>
      <vuln:product>cpe:/h:cisco:network_analysis_module</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1257</vuln:cve-id>
    <vuln:published-datetime>2007-03-03T15:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:48.097-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5188" name="oval:org.mitre.oval:def:5188"/>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20070228-nam.shtml" xml:lang="en">20070228 Cisco Catalyst 6000, 6500 Series and Cisco 7600 Series NAM (Network Analysis Module) Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/472412" xml:lang="en">VU#472412</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22751" xml:lang="en">22751</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017710" xml:lang="en">1017710</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0783" xml:lang="en">ADV-2007-0783</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32750" xml:lang="en">cisco-catalyst-nam-unauthorized-access(32750)</vuln:reference>
    </vuln:references>
    <vuln:summary>The Network Analysis Module (NAM) in Cisco Catalyst Series 6000, 6500, and 7600 allows remote attackers to execute arbitrary commands via certain SNMP packets that are spoofed from the NAM's own IP address.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1258">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_6000"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_6500"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_7600"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/h:cisco:catalyst_6500"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2%2818%29sxf4"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2sxa"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2sxb"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2sxd"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.2sxf"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:cisco:catalyst_6000</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_6500</vuln:product>
      <vuln:product>cpe:/h:cisco:catalyst_7600</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2%2818%29sxf4</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2sxa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2sxb</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2sxd</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.2sxf</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1258</vuln:cve-id>
    <vuln:published-datetime>2007-03-03T15:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:48.157-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.1</cvss:score>
        <cvss:access-vector>ADJACENT_NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5869" name="oval:org.mitre.oval:def:5869"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/707/cisco-sa-20070228-mpls.shtml" xml:lang="en">20070228 Cisco Catalyst 6000, 6500 and Cisco 7600 Series MPLS Packet Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017709" xml:lang="en">1017709</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0782" xml:lang="en">ADV-2007-0782</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32748" xml:lang="en">cisco-catalyst-mpls-dos(32748)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Cisco IOS 12.2SXA, SXB, SXD, and SXF; and the MSFC2, MSFC2a and MSFC3 running in Hybrid Mode on Cisco Catalyst 6000, 6500 and Cisco 7600 series systems; allows remote attackers on a local network segment to cause a denial of service (software reload) via a certain MPLS packet.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1259">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.2"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.3"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.4"/>
        <cpe-lang:fact-ref name="cpe:/a:web-app.org:webapp:0.9.9.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.1</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.2</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.2.1</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.3</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.3.1</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.3.2</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.4</vuln:product>
      <vuln:product>cpe:/a:web-app.org:webapp:0.9.9.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1259</vuln:cve-id>
    <vuln:published-datetime>2007-03-03T15:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-09-01T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2007-03-07T10:53:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0720" xml:lang="en">ADV-2007-0720</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=252" xml:lang="en">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=252</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=254" xml:lang="en">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=254</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple unspecified vulnerabilities in WebAPP before 0.9.9.6 have unknown impact and attack vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1260">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:webmod:webmod:0.48"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:webmod:webmod:0.48</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1260</vuln:cve-id>
    <vuln:published-datetime>2007-03-03T16:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:48.220-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://cybermind.user.stfunoob.com/w48crash/" xml:lang="en">http://cybermind.user.stfunoob.com/w48crash/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22788" xml:lang="en">22788</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32755" xml:lang="en">webmod-contentlength-bo(32755)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3395" xml:lang="en">3395</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in the connectHandle function in server.cpp in WebMod 0.48 allows remote attackers to execute arbitrary code via a long string in the Content-Length HTTP header.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1261">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:openbiblio:openbiblio:0.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:openbiblio:openbiblio:0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:openbiblio:openbiblio:0.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:openbiblio:openbiblio:0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:openbiblio:openbiblio:0.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:openbiblio:openbiblio:0.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:openbiblio:openbiblio:0.5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:openbiblio:openbiblio:0.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:openbiblio:openbiblio:0.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:openbiblio:openbiblio:0.5.2:pre4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:openbiblio:openbiblio:0.1.0</vuln:product>
      <vuln:product>cpe:/a:openbiblio:openbiblio:0.2</vuln:product>
      <vuln:product>cpe:/a:openbiblio:openbiblio:0.2.1</vuln:product>
      <vuln:product>cpe:/a:openbiblio:openbiblio:0.3</vuln:product>
      <vuln:product>cpe:/a:openbiblio:openbiblio:0.3.0</vuln:product>
      <vuln:product>cpe:/a:openbiblio:openbiblio:0.4.0</vuln:product>
      <vuln:product>cpe:/a:openbiblio:openbiblio:0.5.0</vuln:product>
      <vuln:product>cpe:/a:openbiblio:openbiblio:0.5.1</vuln:product>
      <vuln:product>cpe:/a:openbiblio:openbiblio:0.5.2</vuln:product>
      <vuln:product>cpe:/a:openbiblio:openbiblio:0.5.2:pre4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1261</vuln:cve-id>
    <vuln:published-datetime>2007-03-03T16:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:42.297-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?group_id=50071&amp;release_id=488061" xml:lang="en">http://sourceforge.net/project/shownotes.php?group_id=50071&amp;release_id=488061</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0790" xml:lang="en">ADV-2007-0790</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32758" xml:lang="en">openbiblio-reports-privilege-escalation(32758)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the reports system in OpenBiblio before 0.6.0 allows attackers to gain privileges via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1262">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.3_r3"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.3_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.3a"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.3aa"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.4_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.6_cvs"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.6_rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.7"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.8"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.9"/>
        <cpe-lang:fact-ref name="cpe:/a:squirrelmail:squirrelmail:1.4.9a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.0</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.1</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.2</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.3</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.3_r3</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.3_rc1</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.3a</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.3aa</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.4</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.4_rc1</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.5</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.6</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.6_cvs</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.6_rc1</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.7</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.8</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.9</vuln:product>
      <vuln:product>cpe:/a:squirrelmail:squirrelmail:1.4.9a</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1262</vuln:cve-id>
    <vuln:published-datetime>2007-05-11T00:20:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:48.283-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11712" name="oval:org.mitre.oval:def:11712"/>
    <vuln:cwe id="CWE-79"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=306172" xml:lang="en">http://docs.info.apple.com/article.html?artnum=306172</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>JVN</vuln:source>
      <vuln:reference href="http://jvn.jp/en/jp/JVN09157962/index.html" xml:lang="en">JVN#09157962</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>JVNDB</vuln:source>
      <vuln:reference href="http://jvndb.jvn.jp/ja/contents/2007/JVNDB-2007-000398.html" xml:lang="en">JVNDB-2007-000398</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html" xml:lang="en">APPLE-SA-2007-07-31</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1290" xml:lang="en">DSA-1290</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:106" xml:lang="en">MDKSA-2007:106</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_13_sr.html" xml:lang="en">SUSE-SR:2007:013</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23910" xml:lang="en">23910</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/25159" xml:lang="en">25159</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018033" xml:lang="en">1018033</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.squirrelmail.org/security/issue/2007-05-09" xml:lang="en">http://www.squirrelmail.org/security/issue/2007-05-09</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1748" xml:lang="en">ADV-2007-1748</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2732" xml:lang="en">ADV-2007-2732</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1353" xml:lang="en">https://issues.rpath.com/browse/RPL-1353</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="https://rhn.redhat.com/errata/RHSA-2007-0358.html" xml:lang="en">RHSA-2007:0358</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in the HTML filter in SquirrelMail 1.4.0 through 1.4.9a allow remote attackers to inject arbitrary web script or HTML via the (1) data: URI in an HTML e-mail attachment or (2) various non-ASCII character sets that are not properly filtered when viewed with Microsoft Internet Explorer.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1263">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gnu:gpgme:1.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:gnupg:gnupg:1.4.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnu:gpgme:1.1.3</vuln:product>
      <vuln:product>cpe:/a:gnupg:gnupg:1.4.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1263</vuln:cve-id>
    <vuln:published-datetime>2007-03-06T15:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:38.643-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10496" name="oval:org.mitre.oval:def:10496"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" xml:lang="en">20070301-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2775" xml:lang="en">FEDORA-2007-316</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2776" xml:lang="en">FEDORA-2007-315</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.gnupg.org/pipermail/gnupg-users/2007-March/030514.html" xml:lang="en">[gnupg-users] 20070306 [Announce] Multiple Messages Problem in GnuPG and GPGME</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0008.html" xml:lang="en">SUSE-SA:2007:024</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2353" xml:lang="en">2353</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2007-144.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2007-144.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.coresecurity.com/?action=item&amp;id=1687" xml:lang="en">http://www.coresecurity.com/?action=item&amp;id=1687</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1266" xml:lang="en">DSA-1266</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:059" xml:lang="en">MDKSA-2007:059</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0106.html" xml:lang="en">RHSA-2007:0106</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0107.html" xml:lang="en">RHSA-2007:0107</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461958/100/0/threaded" xml:lang="en">20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461958/30/7710/threaded" xml:lang="en">20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22757" xml:lang="en">22757</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017727" xml:lang="en">1017727</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2007/0009/" xml:lang="en">2007-0009</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-432-1" xml:lang="en">USN-432-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-432-2" xml:lang="en">USN-432-2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0835" xml:lang="en">ADV-2007-0835</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1111" xml:lang="en">https://issues.rpath.com/browse/RPL-1111</vuln:reference>
    </vuln:references>
    <vuln:summary>GnuPG 1.4.6 and earlier and GPGME before 1.1.4, when run from the command line, does not visually distinguish signed and unsigned portions of OpenPGP messages with multiple components, which might allow remote attackers to forge the contents of a message without detection.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1264">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:enigmail:enigmail:0.94.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:enigmail:enigmail:0.94.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1264</vuln:cve-id>
    <vuln:published-datetime>2007-03-06T15:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:40.283-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.gnupg.org/pipermail/gnupg-users/2007-March/030514.html" xml:lang="en">[gnupg-users] 20070306 [Announce] Multiple Messages Problem in GnuPG and GPGME</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2353" xml:lang="en">2353</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.coresecurity.com/?action=item&amp;id=1687" xml:lang="en">http://www.coresecurity.com/?action=item&amp;id=1687</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461958/100/0/threaded" xml:lang="en">20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461958/30/7710/threaded" xml:lang="en">20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22758" xml:lang="en">22758</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017727" xml:lang="en">1017727</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0835" xml:lang="en">ADV-2007-0835</vuln:reference>
    </vuln:references>
    <vuln:summary>Enigmail 0.94.2 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Enigmail from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1265">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:kde:k-mail:0.0.29.2"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:k-mail:1.0.23"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:k-mail:1.0.24"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:k-mail:1.0.25"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:k-mail:1.0.26"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:k-mail:1.0.27"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:k-mail:1.0.28"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:k-mail:1.0.29"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:k-mail:1.0.29.1"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:k-mail:1.0.29.2"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:k-mail:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:k-mail:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:k-mail:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:k-mail:1.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:k-mail:1.9.1"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:k-mail:1.86.2.36"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:k-mail:1.87"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:k-mail:1.88"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:k-mail:1.89"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:k-mail:1.90"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:k-mail:1.92"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:k-mail:1.93"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:k-mail:1.94"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:k-mail:1.95"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:k-mail:1.101"/>
        <cpe-lang:fact-ref name="cpe:/a:kde:k-mail:1.102"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kde:k-mail:0.0.29.2</vuln:product>
      <vuln:product>cpe:/a:kde:k-mail:1.0.23</vuln:product>
      <vuln:product>cpe:/a:kde:k-mail:1.0.24</vuln:product>
      <vuln:product>cpe:/a:kde:k-mail:1.0.25</vuln:product>
      <vuln:product>cpe:/a:kde:k-mail:1.0.26</vuln:product>
      <vuln:product>cpe:/a:kde:k-mail:1.0.27</vuln:product>
      <vuln:product>cpe:/a:kde:k-mail:1.0.28</vuln:product>
      <vuln:product>cpe:/a:kde:k-mail:1.0.29</vuln:product>
      <vuln:product>cpe:/a:kde:k-mail:1.0.29.1</vuln:product>
      <vuln:product>cpe:/a:kde:k-mail:1.0.29.2</vuln:product>
      <vuln:product>cpe:/a:kde:k-mail:1.1</vuln:product>
      <vuln:product>cpe:/a:kde:k-mail:1.2</vuln:product>
      <vuln:product>cpe:/a:kde:k-mail:1.3.1</vuln:product>
      <vuln:product>cpe:/a:kde:k-mail:1.7.1</vuln:product>
      <vuln:product>cpe:/a:kde:k-mail:1.9.1</vuln:product>
      <vuln:product>cpe:/a:kde:k-mail:1.86.2.36</vuln:product>
      <vuln:product>cpe:/a:kde:k-mail:1.87</vuln:product>
      <vuln:product>cpe:/a:kde:k-mail:1.88</vuln:product>
      <vuln:product>cpe:/a:kde:k-mail:1.89</vuln:product>
      <vuln:product>cpe:/a:kde:k-mail:1.90</vuln:product>
      <vuln:product>cpe:/a:kde:k-mail:1.92</vuln:product>
      <vuln:product>cpe:/a:kde:k-mail:1.93</vuln:product>
      <vuln:product>cpe:/a:kde:k-mail:1.94</vuln:product>
      <vuln:product>cpe:/a:kde:k-mail:1.95</vuln:product>
      <vuln:product>cpe:/a:kde:k-mail:1.101</vuln:product>
      <vuln:product>cpe:/a:kde:k-mail:1.102</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1265</vuln:cve-id>
    <vuln:published-datetime>2007-03-06T15:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:40.673-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.gnupg.org/pipermail/gnupg-users/2007-March/030514.html" xml:lang="en">[gnupg-users] 20070306 [Announce] Multiple Messages Problem in GnuPG and GPGME</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2353" xml:lang="en">2353</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.coresecurity.com/?action=item&amp;id=1687" xml:lang="en">http://www.coresecurity.com/?action=item&amp;id=1687</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461958/100/0/threaded" xml:lang="en">20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461958/30/7710/threaded" xml:lang="en">20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22759" xml:lang="en">22759</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017727" xml:lang="en">1017727</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0835" xml:lang="en">ADV-2007-0835</vuln:reference>
    </vuln:references>
    <vuln:summary>KMail 1.9.5 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents KMail from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1266">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gnome:evolution:2.8.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnome:evolution:2.8.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1266</vuln:cve-id>
    <vuln:published-datetime>2007-03-06T15:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:41.097-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.gnupg.org/pipermail/gnupg-users/2007-March/030514.html" xml:lang="en">[gnupg-users] 20070306 [Announce] Multiple Messages Problem in GnuPG and GPGME</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2353" xml:lang="en">2353</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.coresecurity.com/?action=item&amp;id=1687" xml:lang="en">http://www.coresecurity.com/?action=item&amp;id=1687</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461958/100/0/threaded" xml:lang="en">20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461958/30/7710/threaded" xml:lang="en">20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22760" xml:lang="en">22760</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017727" xml:lang="en">1017727</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0835" xml:lang="en">ADV-2007-0835</vuln:reference>
    </vuln:references>
    <vuln:summary>Evolution 2.8.1 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Evolution from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1267">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:sylpheed:sylpheed:2.2.7"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sylpheed:sylpheed:2.2.7</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1267</vuln:cve-id>
    <vuln:published-datetime>2007-03-06T15:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:41.470-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.gnupg.org/pipermail/gnupg-users/2007-March/030514.html" xml:lang="en">[gnupg-users] 20070306 [Announce] Multiple Messages Problem in GnuPG and GPGME</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2353" xml:lang="en">2353</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.coresecurity.com/?action=item&amp;id=1687" xml:lang="en">http://www.coresecurity.com/?action=item&amp;id=1687</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461958/100/0/threaded" xml:lang="en">20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461958/30/7710/threaded" xml:lang="en">20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22777" xml:lang="en">22777</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017727" xml:lang="en">1017727</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0835" xml:lang="en">ADV-2007-0835</vuln:reference>
    </vuln:references>
    <vuln:summary>Sylpheed 2.2.7 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Sylpheed from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1268">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mutt:mutt:1.5.13"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mutt:mutt:1.5.13</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1268</vuln:cve-id>
    <vuln:published-datetime>2007-03-06T15:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:41.847-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.gnupg.org/pipermail/gnupg-users/2007-March/030514.html" xml:lang="en">[gnupg-users] 20070306 [Announce] Multiple Messages Problem in GnuPG and GPGME</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2353" xml:lang="en">2353</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.coresecurity.com/?action=item&amp;id=1687" xml:lang="en">http://www.coresecurity.com/?action=item&amp;id=1687</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461958/100/0/threaded" xml:lang="en">20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461958/30/7710/threaded" xml:lang="en">20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22778" xml:lang="en">22778</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017727" xml:lang="en">1017727</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0835" xml:lang="en">ADV-2007-0835</vuln:reference>
    </vuln:references>
    <vuln:summary>Mutt 1.5.13 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Mutt from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1269">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:gnu:gnumail:1.1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnu:gnumail:1.1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1269</vuln:cve-id>
    <vuln:published-datetime>2007-03-06T15:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:42.203-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.gnupg.org/pipermail/gnupg-users/2007-March/030514.html" xml:lang="en">[gnupg-users] 20070306 [Announce] Multiple Messages Problem in GnuPG and GPGME</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2353" xml:lang="en">2353</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.coresecurity.com/?action=item&amp;id=1687" xml:lang="en">http://www.coresecurity.com/?action=item&amp;id=1687</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461958/100/0/threaded" xml:lang="en">20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461958/30/7710/threaded" xml:lang="en">20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22779" xml:lang="en">22779</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017727" xml:lang="en">1017727</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0835" xml:lang="en">ADV-2007-0835</vuln:reference>
    </vuln:references>
    <vuln:summary>GNUMail 1.1.2 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents GNUMail from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1270">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:vmware:esx_server:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:vmware:esx:3.0.0"/>
        <cpe-lang:fact-ref name="cpe:/o:vmware:esx:3.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vmware:esx_server:3.0</vuln:product>
      <vuln:product>cpe:/o:vmware:esx:3.0.0</vuln:product>
      <vuln:product>cpe:/o:vmware:esx:3.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1270</vuln:cve-id>
    <vuln:published-datetime>2007-04-05T20:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:23.590-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5463" name="oval:org.mitre.oval:def:5463"/>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2524" xml:lang="en">2524</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/464745/100/0/threaded" xml:lang="en">20070404 VMSA-2007-0003 VMware ESX 3.0.1 and 3.0.0 server security updates</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23323" xml:lang="en">23323</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017875" xml:lang="en">1017875</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/vi3/doc/esx-5754280-patch.html" xml:lang="en">http://www.vmware.com/support/vi3/doc/esx-5754280-patch.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/vi3/doc/esx-6431040-patch.html" xml:lang="en">http://www.vmware.com/support/vi3/doc/esx-6431040-patch.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1267" xml:lang="en">ADV-2007-1267</vuln:reference>
    </vuln:references>
    <vuln:summary>Double free vulnerability in VMware ESX Server 3.0.0 and 3.0.1 allows attackers to cause a denial of service (crash), obtain sensitive information, or possibly execute arbitrary code via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1271">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:vmware:esx:3.0.0"/>
        <cpe-lang:fact-ref name="cpe:/o:vmware:esx:3.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:vmware:esx:3.0.0</vuln:product>
      <vuln:product>cpe:/o:vmware:esx:3.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1271</vuln:cve-id>
    <vuln:published-datetime>2007-04-05T20:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:26:23.590-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5552" name="oval:org.mitre.oval:def:5552"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2524" xml:lang="en">2524</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/464745/100/0/threaded" xml:lang="en">20070404 VMSA-2007-0003 VMware ESX 3.0.1 and 3.0.0 server security updates</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23322" xml:lang="en">23322</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017875" xml:lang="en">1017875</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/vi3/doc/esx-5754280-patch.html" xml:lang="en">http://www.vmware.com/support/vi3/doc/esx-5754280-patch.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/vi3/doc/esx-6431040-patch.html" xml:lang="en">http://www.vmware.com/support/vi3/doc/esx-6431040-patch.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1267" xml:lang="en">ADV-2007-1267</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in VMware ESX Server 3.0.0 and 3.0.1 might allow attackers to gain privileges or cause a denial of service (application crash) via unspecified vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1273">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:2.0"/>
          <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:2.0.1"/>
          <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:2.0.2"/>
          <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:2.0.3"/>
          <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:2.0.4"/>
          <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:2.1"/>
          <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:3.0.1"/>
          <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:4.0"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:navision:financials_server:3.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:navision:financials_server:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1273</vuln:cve-id>
    <vuln:published-datetime>2007-03-10T15:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-10-14T00:56:15.297-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NETBSD</vuln:source>
      <vuln:reference href="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2007-001.txt.asc" xml:lang="en">NetBSD-SA2007-001</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22878" xml:lang="en">22878</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in the ktruser function in NetBSD-current before 20061022, NetBSD 3 and 3-0 before 20061024, and NetBSD 2 before 20070209, when the kernel is built with the COMPAT_FREEBSD or COMPAT_DARWIN option, allows local users to cause a denial of service and possibly gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1276">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:1.000"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:1.010"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:1.020"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:1.030"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:1.040"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:1.051"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:1.060"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:1.070"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:1.080"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:1.090"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:1.100"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:1.110"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:1.120"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:1.130"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:1.140"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:1.150"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:1.210"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:1.220"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:1.230"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:1.240"/>
        <cpe-lang:fact-ref name="cpe:/a:usermin:usermin:1.250"/>
        <cpe-lang:fact-ref name="cpe:/a:webmin:webmin:1.0.00"/>
        <cpe-lang:fact-ref name="cpe:/a:webmin:webmin:1.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:webmin:webmin:1.0.20"/>
        <cpe-lang:fact-ref name="cpe:/a:webmin:webmin:1.0.30"/>
        <cpe-lang:fact-ref name="cpe:/a:webmin:webmin:1.0.40"/>
        <cpe-lang:fact-ref name="cpe:/a:webmin:webmin:1.0.50"/>
        <cpe-lang:fact-ref name="cpe:/a:webmin:webmin:1.0.51"/>
        <cpe-lang:fact-ref name="cpe:/a:webmin:webmin:1.0.60"/>
        <cpe-lang:fact-ref name="cpe:/a:webmin:webmin:1.0.70"/>
        <cpe-lang:fact-ref name="cpe:/a:webmin:webmin:1.0.80"/>
        <cpe-lang:fact-ref name="cpe:/a:webmin:webmin:1.0.90"/>
        <cpe-lang:fact-ref name="cpe:/a:webmin:webmin:1.1.00"/>
        <cpe-lang:fact-ref name="cpe:/a:webmin:webmin:1.1.10"/>
        <cpe-lang:fact-ref name="cpe:/a:webmin:webmin:1.1.20"/>
        <cpe-lang:fact-ref name="cpe:/a:webmin:webmin:1.1.21"/>
        <cpe-lang:fact-ref name="cpe:/a:webmin:webmin:1.1.30"/>
        <cpe-lang:fact-ref name="cpe:/a:webmin:webmin:1.1.40"/>
        <cpe-lang:fact-ref name="cpe:/a:webmin:webmin:1.1.50"/>
        <cpe-lang:fact-ref name="cpe:/a:webmin:webmin:1.2.20"/>
        <cpe-lang:fact-ref name="cpe:/a:webmin:webmin:1.2.30"/>
        <cpe-lang:fact-ref name="cpe:/a:webmin:webmin:1.2.40"/>
        <cpe-lang:fact-ref name="cpe:/a:webmin:webmin:1.2.50"/>
        <cpe-lang:fact-ref name="cpe:/a:webmin:webmin:1.3.20"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:usermin:usermin:1.000</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:1.010</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:1.020</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:1.030</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:1.040</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:1.051</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:1.060</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:1.070</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:1.080</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:1.090</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:1.100</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:1.110</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:1.120</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:1.130</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:1.140</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:1.150</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:1.210</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:1.220</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:1.230</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:1.240</vuln:product>
      <vuln:product>cpe:/a:usermin:usermin:1.250</vuln:product>
      <vuln:product>cpe:/a:webmin:webmin:1.0.00</vuln:product>
      <vuln:product>cpe:/a:webmin:webmin:1.0.10</vuln:product>
      <vuln:product>cpe:/a:webmin:webmin:1.0.20</vuln:product>
      <vuln:product>cpe:/a:webmin:webmin:1.0.30</vuln:product>
      <vuln:product>cpe:/a:webmin:webmin:1.0.40</vuln:product>
      <vuln:product>cpe:/a:webmin:webmin:1.0.50</vuln:product>
      <vuln:product>cpe:/a:webmin:webmin:1.0.51</vuln:product>
      <vuln:product>cpe:/a:webmin:webmin:1.0.60</vuln:product>
      <vuln:product>cpe:/a:webmin:webmin:1.0.70</vuln:product>
      <vuln:product>cpe:/a:webmin:webmin:1.0.80</vuln:product>
      <vuln:product>cpe:/a:webmin:webmin:1.0.90</vuln:product>
      <vuln:product>cpe:/a:webmin:webmin:1.1.00</vuln:product>
      <vuln:product>cpe:/a:webmin:webmin:1.1.10</vuln:product>
      <vuln:product>cpe:/a:webmin:webmin:1.1.20</vuln:product>
      <vuln:product>cpe:/a:webmin:webmin:1.1.21</vuln:product>
      <vuln:product>cpe:/a:webmin:webmin:1.1.30</vuln:product>
      <vuln:product>cpe:/a:webmin:webmin:1.1.40</vuln:product>
      <vuln:product>cpe:/a:webmin:webmin:1.1.50</vuln:product>
      <vuln:product>cpe:/a:webmin:webmin:1.2.20</vuln:product>
      <vuln:product>cpe:/a:webmin:webmin:1.2.30</vuln:product>
      <vuln:product>cpe:/a:webmin:webmin:1.2.40</vuln:product>
      <vuln:product>cpe:/a:webmin:webmin:1.2.50</vuln:product>
      <vuln:product>cpe:/a:webmin:webmin:1.3.20</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1276</vuln:cve-id>
    <vuln:published-datetime>2007-03-05T15:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:42.360-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-352"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017711" xml:lang="en">1017711</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0780" xml:lang="en">ADV-2007-0780</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.webmin.com/changes-1.330.html" xml:lang="en">http://www.webmin.com/changes-1.330.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.webmin.com/security.html" xml:lang="en">http://www.webmin.com/security.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32725" xml:lang="en">webmin-chooser-xss(32725)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in chooser.cgi in Webmin before 1.330 and Usermin before 1.260 allow remote attackers to inject arbitrary web script or HTML via a crafted filename.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1277">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:wordpress:wordpress:2.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:wordpress:wordpress:2.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1277</vuln:cve-id>
    <vuln:published-datetime>2007-03-05T15:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:43.470-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://ifsec.blogspot.com/2007/03/wordpress-code-compromised-to-enable.html" xml:lang="en">http://ifsec.blogspot.com/2007/03/wordpress-code-compromised-to-enable.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://wordpress.org/development/2007/03/upgrade-212/" xml:lang="en">http://wordpress.org/development/2007/03/upgrade-212/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/214480" xml:lang="en">VU#214480</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/641456" xml:lang="en">VU#641456</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461794/100/0/threaded" xml:lang="en">20070303 WordPress source code compromised to enable remote code execution</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22797" xml:lang="en">22797</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0812" xml:lang="en">ADV-2007-0812</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32804" xml:lang="en">wordpress-feed-code-execution(32804)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32807" xml:lang="en">wordpress-theme-command-execution(32807)</vuln:reference>
    </vuln:references>
    <vuln:summary>WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externally introduced backdoor that allows remote attackers to execute arbitrary commands via (1) an eval injection vulnerability in the ix parameter to wp-includes/feed.php, and (2) an untrusted passthru call in the iz parameter to wp-includes/theme.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1278">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:6.0"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:adobe:coldfusion:6.1::enterprise_server"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:coldfusion:7.0::enterprise_server"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:jrun:4.0:updater6"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:coldfusion:6.1::enterprise_server</vuln:product>
      <vuln:product>cpe:/a:adobe:coldfusion:7.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/a:adobe:jrun:4.0:updater6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1278</vuln:cve-id>
    <vuln:published-datetime>2007-03-16T16:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2019-07-03T13:25:47.480-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb07-07.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb07-07.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22958" xml:lang="en">22958</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017752" xml:lang="en">1017752</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0932" xml:lang="en">ADV-2007-0932</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32994" xml:lang="en">coldfusion-jrun-iisconnector-dos(32994)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the IIS connector in Adobe JRun 4.0 Updater 6, and ColdFusion MX 6.1 and 7.0 Enterprise, when using Microsoft IIS 6, allows remote attackers to cause a denial of service via unspecified vectors, involving the request of a file in the JRun web root.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1279">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:apple:mac_os_x"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:adobe:bridge:1.0.3"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:bridge:1.0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1279</vuln:cve-id>
    <vuln:published-datetime>2007-04-11T18:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:42.547-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb07-09.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb07-09.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23404" xml:lang="en">23404</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017900" xml:lang="en">1017900</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1342" xml:lang="en">ADV-2007-1342</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33570" xml:lang="en">bridge-unspecified-privilege-escalation(33570)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the installer for Adobe Bridge 1.0.3 update for Apple OS X, when patching with desktop management tools, allows local users to gain privileges via unspecified vectors during installation of the update by a different user who has administrative privileges.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1280">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:all_windows"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:adobe:robohelp:6"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:robohelp:x5"/>
          <cpe-lang:fact-ref name="cpe:/a:adobe:robohelp_server:6"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:robohelp:6</vuln:product>
      <vuln:product>cpe:/a:adobe:robohelp:x5</vuln:product>
      <vuln:product>cpe:/a:adobe:robohelp_server:6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1280</vuln:cve-id>
    <vuln:published-datetime>2007-05-09T20:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:43.940-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.adobe.com/support/security/bulletins/apsb07-10.html" xml:lang="en">http://www.adobe.com/support/security/bulletins/apsb07-10.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.devtarget.org/adobe-advisory-05-2007.txt" xml:lang="en">http://www.devtarget.org/adobe-advisory-05-2007.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/468360/100/0/threaded" xml:lang="en">20070511 Cross-Site Scripting in Adobe RoboHelp 6, Server 6 and X5</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23878" xml:lang="en">23878</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018020" xml:lang="en">1018020</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1714" xml:lang="en">ADV-2007-1714</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/34181" xml:lang="en">robohelp-files-xss(34181)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in Adobe RoboHelp X5, 6, and Server 6 allows remote attackers to inject arbitrary web script or HTML via a URL after a # (hash) in the URL path, as demonstrated using en/frameset-7.html, and possibly other unspecified vectors involving templates and (1) whstart.js and (2) whcsh_home.htm in WebHelp, (3) wf_startpage.js and (4) wf_startqs.htm in FlashHelp, or (5) WindowManager.dll in RoboHelp Server 6.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1281">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:all_windows:abstract_cpe"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:kaspersky_lab:kaspersky_antivirus_engine:6.0.1.411"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:::ia32_64-bit"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:kaspersky_lab:kaspersky_antivirus_engine:5.5.10"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kaspersky_lab:kaspersky_antivirus_engine:5.5.10</vuln:product>
      <vuln:product>cpe:/a:kaspersky_lab:kaspersky_antivirus_engine:6.0.1.411</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1281</vuln:cve-id>
    <vuln:published-datetime>2007-03-05T20:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:42.673-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=485" xml:lang="en">20070302 Kaspersky AntiVirus UPX File Decompression DoS Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22795" xml:lang="en">22795</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017718" xml:lang="en">1017718</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0810" xml:lang="en">ADV-2007-0810</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32797" xml:lang="en">kaspersky-upx-dos(32797)</vuln:reference>
    </vuln:references>
    <vuln:summary>Kaspersky AntiVirus Engine 6.0.1.411 for Windows and 5.5-10 for Linux allows remote attackers to cause a denial of service (CPU consumption) via a crafted UPX compressed file with a negative offset, which triggers an infinite loop during decompression.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1282">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::advanced_server"/>
          <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::enterprise_server"/>
          <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::workstation"/>
          <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_desktop:4.0"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:seamonkey:1.0.7"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.7.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:0.9"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.7"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.1"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.2"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.3"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.4"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.6"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.7"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.8"/>
          <cpe-lang:fact-ref name="cpe:/a:mozilla:thunderbird:1.5.0.9"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:seamonkey:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.7.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:0.9</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.1</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.2</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.3</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.4</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.6</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.7</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.8</vuln:product>
      <vuln:product>cpe:/a:mozilla:thunderbird:1.5.0.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1282</vuln:cve-id>
    <vuln:published-datetime>2007-03-05T21:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:48.597-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11313" name="oval:org.mitre.oval:def:11313"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc" xml:lang="en">20070202-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2747" xml:lang="en">FEDORA-2007-308</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="http://fedoranews.org/cms/node/2749" xml:lang="en">FEDORA-2007-309</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200703-18.xml" xml:lang="en">GLSA-200703-18</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131" xml:lang="en">SSA:2007-066-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.363947" xml:lang="en">SSA:2007-066-04</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1336" xml:lang="en">DSA-1336</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mozilla.org/security/announce/2007/mfsa2007-10.html" xml:lang="en">http://www.mozilla.org/security/announce/2007/mfsa2007-10.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0078.html" xml:lang="en">RHSA-2007:0078</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0108.html" xml:lang="en">RHSA-2007:0108</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22845" xml:lang="en">22845</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0824" xml:lang="en">ADV-2007-0824</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="https://bugzilla.mozilla.org/show_bug.cgi?id=362735" xml:lang="en">https://bugzilla.mozilla.org/show_bug.cgi?id=362735</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32810" xml:lang="en">mozilla-email-messages-overflow(32810)</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in Mozilla Thunderbird before 1.5.0.10 and SeaMonkey before 1.0.8 allows remote attackers to trigger a buffer overflow and possibly execute arbitrary code via a text/enhanced or text/richtext e-mail message with an extremely long line.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1285">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.1:patch1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.1:patch2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.3:patch1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.4:patch1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7:rc1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7:rc2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7:rc3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.0.7:rc4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.7"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.8"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.9"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.10"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.1.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:5.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:zend:engine"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:php:4.0.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.1:patch1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.1:patch2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.3:patch1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.4:patch1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.5</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.6</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7:rc1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7:rc2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7:rc3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.0.7:rc4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.1.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.2.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.5</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.6</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.7</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.8</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.9</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.10</vuln:product>
      <vuln:product>cpe:/a:php:php:4.3.11</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.0</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.1</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.2</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.3</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.5</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.6</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.4</vuln:product>
      <vuln:product>cpe:/a:php:php:5.0.5</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.0</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.1</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.2</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.3</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.4</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.5</vuln:product>
      <vuln:product>cpe:/a:php:php:5.1.6</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.0</vuln:product>
      <vuln:product>cpe:/a:php:php:5.2.1</vuln:product>
      <vuln:product>cpe:/a:zend:engine</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1285</vuln:cve-id>
    <vuln:published-datetime>2007-03-06T15:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-30T12:25:35.747-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11017" name="oval:org.mitre.oval:def:11017"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2007-07/msg00006.html" xml:lang="en">SUSE-SA:2007:044</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2007-0154.html" xml:lang="en">RHSA-2007:0154</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2007-0155.html" xml:lang="en">RHSA-2007:0155</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2007-0163.html" xml:lang="en">RHSA-2007:0163</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200705-19.xml" xml:lang="en">GLSA-200705-19</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2008&amp;m=slackware-security.335136" xml:lang="en">SSA:2008-045-03</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://us2.php.net/releases/4_4_7.php" xml:lang="en">http://us2.php.net/releases/4_4_7.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://us2.php.net/releases/5_2_2.php" xml:lang="en">http://us2.php.net/releases/5_2_2.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:087" xml:lang="en">MDKSA-2007:087</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:088" xml:lang="en">MDKSA-2007:088</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:089" xml:lang="en">MDKSA-2007:089</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:090" xml:lang="en">MDKSA-2007:090</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.php.net/ChangeLog-4.php" xml:lang="en">http://www.php.net/ChangeLog-4.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.php.net/ChangeLog-5.php#5.2.4" xml:lang="en">http://www.php.net/ChangeLog-5.php#5.2.4</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.php.net/releases/4_4_8.php" xml:lang="en">http://www.php.net/releases/4_4_8.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.php.net/releases/5_2_4.php" xml:lang="en">http://www.php.net/releases/5_2_4.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.php-security.org/MOPB/MOPB-03-2007.html" xml:lang="en">http://www.php-security.org/MOPB/MOPB-03-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0082.html" xml:lang="en">RHSA-2007:0082</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0162.html" xml:lang="en">RHSA-2007:0162</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/466166/100/0/threaded" xml:lang="en">20070418 rPSA-2007-0073-1 php php-mysql php-pgsql</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22764" xml:lang="en">22764</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017771" xml:lang="en">1017771</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-549-2" xml:lang="en">USN-549-2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1268" xml:lang="en">https://issues.rpath.com/browse/RPL-1268</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://launchpad.net/bugs/173043" xml:lang="en">https://launchpad.net/bugs/173043</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="https://usn.ubuntu.com/549-1/" xml:lang="en">USN-549-1</vuln:reference>
    </vuln:references>
    <vuln:summary>The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHP crash) via deeply nested arrays, which trigger deep recursion in the variable destruction routines.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1286">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:php:4.4.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1286</vuln:cve-id>
    <vuln:published-datetime>2007-03-06T15:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:48.453-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11575" name="oval:org.mitre.oval:def:11575"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01056506" xml:lang="en">SSRT071423</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01086137" xml:lang="en">HPSBTU02232</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2007-0154.html" xml:lang="en">RHSA-2007:0154</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2007-0155.html" xml:lang="en">RHSA-2007:0155</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2007-0163.html" xml:lang="en">RHSA-2007:0163</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200703-21.xml" xml:lang="en">GLSA-200703-21</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200705-19.xml" xml:lang="en">GLSA-200705-19</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1282" xml:lang="en">DSA-1282</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1283" xml:lang="en">DSA-1283</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:087" xml:lang="en">MDKSA-2007:087</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:088" xml:lang="en">MDKSA-2007:088</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.php-security.org/MOPB/MOPB-04-2007.html" xml:lang="en">http://www.php-security.org/MOPB/MOPB-04-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/466166/100/0/threaded" xml:lang="en">20070418 rPSA-2007-0073-1 php php-mysql php-pgsql</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22765" xml:lang="en">22765</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2007/0009/" xml:lang="en">2007-0009</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1991" xml:lang="en">ADV-2007-1991</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2374" xml:lang="en">ADV-2007-2374</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32796" xml:lang="en">php-zval-code-execution(32796)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1268" xml:lang="en">https://issues.rpath.com/browse/RPL-1268</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in PHP 4.4.4 and earlier allows remote context-dependent attackers to execute arbitrary code via a long string to the unserialize function, which triggers the overflow in the ZVAL reference counter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1287">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.4"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:4.4.6"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:php:4.4.4</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.5</vuln:product>
      <vuln:product>cpe:/a:php:php:4.4.6</vuln:product>
      <vuln:product>cpe:/a:php:php:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1287</vuln:cve-id>
    <vuln:published-datetime>2007-03-06T15:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:51:40.813-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=306172" xml:lang="en">http://docs.info.apple.com/article.html?artnum=306172</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html" xml:lang="en">APPLE-SA-2007-07-31</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://us2.php.net/releases/4_4_7.php" xml:lang="en">http://us2.php.net/releases/4_4_7.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.php-security.org/MOPB/MOPB-08-2007.html" xml:lang="en">http://www.php-security.org/MOPB/MOPB-08-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/25159" xml:lang="en">25159</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/2732" xml:lang="en">ADV-2007-2732</vuln:reference>
    </vuln:references>
    <vuln:summary>A regression error in the phpinfo function in PHP 4.4.3 to 4.4.6, and PHP 6.0 in CVS, allows remote attackers to conduct cross-site scripting (XSS) attacks via GET, POST, or COOKIE array values, which are not escaped in the phpinfo output, as originally fixed for CVE-2005-3388.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1288">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:webmobo:wbnews:1.4.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:webmobo:wbnews:1.4.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1288</vuln:cve-id>
    <vuln:published-datetime>2007-03-06T19:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:50.923-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2355" xml:lang="en">2355</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461674/100/0/threaded" xml:lang="en">20070301 WB News Remote File Include in all versions</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32774" xml:lang="en">wbnews-multiple-scripts-file-include(32774)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple PHP remote file inclusion vulnerabilities in Webmobo WB News 1.4.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the config[installdir] parameter to (1) comment.php, (2) themes.php, (3) directory.php, and (4) sendmsg.php in admin/.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1289">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:tyger:bug_tracking_system:1.1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:tyger:bug_tracking_system:1.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1289</vuln:cve-id>
    <vuln:published-datetime>2007-03-06T19:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:51.407-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2356" xml:lang="en">2356</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461801/100/0/threaded" xml:lang="en">20070303 Tyger Bug Tracking System Multiple Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22799" xml:lang="en">22799</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0822" xml:lang="en">ADV-2007-0822</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32791" xml:lang="en">tyger-viewbugs-sql-injection(32791)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in ViewBugs.php in Tyger Bug Tracking System (TygerBT) 1.1.3 allows remote attackers to execute arbitrary SQL commands via the s parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1290">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:tyger:bug_tracking_system:1.1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:tyger:bug_tracking_system:1.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1290</vuln:cve-id>
    <vuln:published-datetime>2007-03-06T19:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:43.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32791" xml:lang="en">tyger-viewbugs-sql-injection(32791)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in ViewReport.php in Tyger Bug Tracking System (TygerBT) 1.1.3 allows remote attackers to execute arbitrary SQL commands via the bug parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1291">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:tyger:bug_tracking_system:1.1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:tyger:bug_tracking_system:1.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1291</vuln:cve-id>
    <vuln:published-datetime>2007-03-06T19:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:51.860-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2356" xml:lang="en">2356</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461801/100/0/threaded" xml:lang="en">20070303 Tyger Bug Tracking System Multiple Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22799" xml:lang="en">22799</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0822" xml:lang="en">ADV-2007-0822</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32792" xml:lang="en">tyger-login-register-xss(32792)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in Tyger Bug Tracking System (TygerBT) 1.1.3 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) Login.php and (2) Register.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1292">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:3.5.8"/>
        <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:3.6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:3.6.1"/>
        <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:3.6.2"/>
        <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:3.6.3"/>
        <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:3.6.4"/>
        <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:3.6.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:jelsoft:vbulletin:3.5.8</vuln:product>
      <vuln:product>cpe:/a:jelsoft:vbulletin:3.6.0</vuln:product>
      <vuln:product>cpe:/a:jelsoft:vbulletin:3.6.1</vuln:product>
      <vuln:product>cpe:/a:jelsoft:vbulletin:3.6.2</vuln:product>
      <vuln:product>cpe:/a:jelsoft:vbulletin:3.6.3</vuln:product>
      <vuln:product>cpe:/a:jelsoft:vbulletin:3.6.4</vuln:product>
      <vuln:product>cpe:/a:jelsoft:vbulletin:3.6.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1292</vuln:cve-id>
    <vuln:published-datetime>2007-03-06T19:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:48.860-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22780" xml:lang="en">22780</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vbulletin.com/forum/showthread.php?postid=1314422" xml:lang="en">http://www.vbulletin.com/forum/showthread.php?postid=1314422</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32746" xml:lang="en">vbulletin-inlinemod-sql-injection(32746)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3387" xml:lang="en">3387</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in inlinemod.php in Jelsoft vBulletin before 3.5.8, and before 3.6.5 in the 3.6.x series, might allow remote authenticated users to execute arbitrary SQL commands via the postids parameter.  NOTE: the vendor states that the attack is feasible only in circumstances "almost impossible to achieve."</vuln:summary>
  </entry>
  <entry id="CVE-2007-1293">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:rigter_portal_system:rigter_portal_system:6.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rigter_portal_system:rigter_portal_system:6.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1293</vuln:cve-id>
    <vuln:published-datetime>2007-03-06T19:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:52.283-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/462146/100/0/threaded" xml:lang="en">20070303 RPS 6.2 SQL Injection Exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22813" xml:lang="en">22813</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0813" xml:lang="en">ADV-2007-0813</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32784" xml:lang="en">rps-index-sql-injection(32784)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3403" xml:lang="en">3403</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in Rigter Portal System (RPS) 6.2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the categoria parameter to the top-level URI (index.php), possibly related to ver_descarga.php.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1294">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:divx:divx_web_player:1.3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:divx:divx_web_player:1.3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1294</vuln:cve-id>
    <vuln:published-datetime>2007-03-06T19:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:49.033-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22776" xml:lang="en">22776</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32759" xml:lang="en">divxwebplayer-npdivx32-dos(32759)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3392" xml:lang="en">3392</vuln:reference>
    </vuln:references>
    <vuln:summary>A certain ActiveX control in the DivXBrowserPlugin (npdivx32.dll) in DivX Web Player, as distributed with DivX Player 1.3.0, allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via large values to DivxWP.Resize, related to resizing images.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1295">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:aj_forum:aj_forum:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:aj_forum:aj_forum:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1295</vuln:cve-id>
    <vuln:published-datetime>2007-03-06T19:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:07.083-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22808" xml:lang="en">22808</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0820" xml:lang="en">ADV-2007-0820</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32785" xml:lang="en">ajforum-topictitle-sql-injection(32785)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3411" xml:lang="en">3411</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in topic_title.php in AJ Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the td_id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1296">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:aj_square:aj_classifieds:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:aj_square:aj_classifieds:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1296</vuln:cve-id>
    <vuln:published-datetime>2007-03-06T19:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:49.080-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22808" xml:lang="en">22808</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0833" xml:lang="en">ADV-2007-0833</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32786" xml:lang="en">ajclassifieds-postingdetails-sql-injection(32786)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3410" xml:lang="en">3410</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in postingdetails.php in AJ Classifieds 1.0 allows remote attackers to execute arbitrary SQL commands via the postingid parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1297">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:aj_square:ajdating:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:aj_square:ajdating:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1297</vuln:cve-id>
    <vuln:published-datetime>2007-03-06T19:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:49.157-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22808" xml:lang="en">22808</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/29154" xml:lang="en">29154</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0821" xml:lang="en">ADV-2007-0821</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32788" xml:lang="en">ajdating-viewprofile-sql-injection(32788)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/42326" xml:lang="en">ajdating-userid-sql-injection(42326)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3409" xml:lang="en">3409</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/5593" xml:lang="en">5593</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in view_profile.php in AJDating 1.0 allows remote attackers to execute arbitrary SQL commands via the user_id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1298">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:aj_square:ajauction:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:aj_square:ajauction:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1298</vuln:cve-id>
    <vuln:published-datetime>2007-03-06T19:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:49.220-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22808" xml:lang="en">22808</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0819" xml:lang="en">ADV-2007-0819</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32789" xml:lang="en">ajauctionpro-subcat-sql-injection(32789)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3408" xml:lang="en">3408</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in subcat.php in AJ Auction 1.0 allows remote attackers to execute arbitrary SQL commands via the cate_id parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1299">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mani_stats_reader:mani_stats_reader:1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mani_stats_reader:mani_stats_reader:1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1299</vuln:cve-id>
    <vuln:published-datetime>2007-03-06T19:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:49.283-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22794" xml:lang="en">22794</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32782" xml:lang="en">mani-stats-index-file-include(32782)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3398" xml:lang="en">3398</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in index.php in Mani Stats Reader 1.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the ipath parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1300">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:douran_software_technologies:isputil:3.32.84.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:douran_software_technologies:isputil:3.32.84.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1300</vuln:cve-id>
    <vuln:published-datetime>2007-03-06T19:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:43.640-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32800" xml:lang="en">isputil-activesessions-info-disclosure(32800)</vuln:reference>
    </vuln:references>
    <vuln:summary>DOURAN Software Technologies ISPUtil 3.32.84.1, and possibly earlier versions, stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain user and reseller data via a direct request for scripts/activesessions.ini.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1301">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_enterprise"/>
        <cpe-lang:fact-ref name="cpe:/a:mailenable:mailenable_professional:2.37::professional"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mailenable:mailenable_enterprise</vuln:product>
      <vuln:product>cpe:/a:mailenable:mailenable_professional:2.37::professional</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1301</vuln:cve-id>
    <vuln:published-datetime>2007-03-06T19:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:49.330-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.mailenable.com/hotfix/" xml:lang="en">http://www.mailenable.com/hotfix/</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22792" xml:lang="en">22792</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017739" xml:lang="en">1017739</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0811" xml:lang="en">ADV-2007-0811</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32801" xml:lang="en">mailenable-append-bo(32801)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3397" xml:lang="en">3397</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in the IMAP service in MailEnable Enterprise and Professional Editions 2.37 and earlier allows remote authenticated users to execute arbitrary code via a long argument to the APPEND command.  NOTE: this is probably different than CVE-2006-6423.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1302">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:li-scripts:li-guestbook:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:li-scripts:li-guestbook:1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:li-scripts:li-guestbook:1.1</vuln:product>
      <vuln:product>cpe:/a:li-scripts:li-guestbook:1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1302</vuln:cve-id>
    <vuln:published-datetime>2007-03-06T19:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:52.830-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-89"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://belsec.com/advisories/139/summary.html" xml:lang="en">http://belsec.com/advisories/139/summary.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2348" xml:lang="en">2348</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461912/100/0/threaded" xml:lang="en">20070305 LI-Guestbook SQL Injection Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/483524/100/0/threaded" xml:lang="en">20071109 li-guestbook sql inj</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22821" xml:lang="en">22821</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.security-news.ws/li-sql-injection" xml:lang="en">http://www.security-news.ws/li-sql-injection</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/38369" xml:lang="en">liguestbook-country-sql-injection(38369)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in guestbook.php in LI-Guestbook 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the country parameter.  NOTE: it was later reported that 1.2 is also affected.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1303">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:rrdbrowse:rrdbrowse:1.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rrdbrowse:rrdbrowse:1.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1303</vuln:cve-id>
    <vuln:published-datetime>2007-03-06T19:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:53.453-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2349" xml:lang="en">2349</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.devtarget.org/rrdbrowse-advisory-03-2007.txt" xml:lang="en">http://www.devtarget.org/rrdbrowse-advisory-03-2007.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.rrdbrowse.org/index.php" xml:lang="en">http://www.rrdbrowse.org/index.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461911/100/0/threaded" xml:lang="en">20070304 Arbitrary file disclosure vulnerability in rrdbrowse &lt;= 1.6</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22817" xml:lang="en">22817</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0834" xml:lang="en">ADV-2007-0834</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32793" xml:lang="en">rrdbrowse-file-directory-traversal(32793)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in rb.cgi in RRDBrowse 1.6 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1304">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:savas_place:savas_guestbook:2006-11-23"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:savas_place:savas_guestbook:2006-11-23</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1304</vuln:cve-id>
    <vuln:published-datetime>2007-03-06T19:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:53.940-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://belsec.com/advisories/142/summary.html" xml:lang="en">http://belsec.com/advisories/142/summary.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2350" xml:lang="en">2350</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461910/100/0/threaded" xml:lang="en">20070305 Sava's GuestBook Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22820" xml:lang="en">22820</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32811" xml:lang="en">savasguestbook-add2-sql-injection(32811)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple SQL injection vulnerabilities in add2.php in Sava's Guestbook 23.11.2006, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) name, (2) country, (3) email, (4) website, and (5) message parameters.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1305">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:savas_place:savas_guestbook:2006-11-23"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:savas_place:savas_guestbook:2006-11-23</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1305</vuln:cve-id>
    <vuln:published-datetime>2007-03-06T19:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:54.330-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://belsec.com/advisories/142/summary.html" xml:lang="en">http://belsec.com/advisories/142/summary.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2350" xml:lang="en">2350</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461910/100/0/threaded" xml:lang="en">20070305 Sava's GuestBook Multiple Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22820" xml:lang="en">22820</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32812" xml:lang="en">savasguestbook-add2-xss(32812)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in add2.php in Sava's Guestbook 23.11.2006 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) country, (3) email, and (4) website parameters.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1306">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:digium:asterisk:1.2.0_beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:digium:asterisk:1.2.0_beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:digium:asterisk:1.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:digium:asterisk:1.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:digium:asterisk:1.2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:digium:asterisk:1.2.9"/>
        <cpe-lang:fact-ref name="cpe:/a:digium:asterisk:1.2.10"/>
        <cpe-lang:fact-ref name="cpe:/a:digium:asterisk:1.2.11"/>
        <cpe-lang:fact-ref name="cpe:/a:digium:asterisk:1.2.12"/>
        <cpe-lang:fact-ref name="cpe:/a:digium:asterisk:1.2.12.1"/>
        <cpe-lang:fact-ref name="cpe:/a:digium:asterisk:1.2.13"/>
        <cpe-lang:fact-ref name="cpe:/a:digium:asterisk:1.2.14"/>
        <cpe-lang:fact-ref name="cpe:/a:digium:asterisk:1.2.15"/>
        <cpe-lang:fact-ref name="cpe:/a:digium:asterisk:1.2_beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:digium:asterisk:1.2_beta2"/>
        <cpe-lang:fact-ref name="cpe:/a:digium:asterisk:1.4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:digium:asterisk:1.4.0_beta1"/>
        <cpe-lang:fact-ref name="cpe:/a:digium:asterisk:1.4.0_beta2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:digium:asterisk:1.2.0_beta1</vuln:product>
      <vuln:product>cpe:/a:digium:asterisk:1.2.0_beta2</vuln:product>
      <vuln:product>cpe:/a:digium:asterisk:1.2.6</vuln:product>
      <vuln:product>cpe:/a:digium:asterisk:1.2.7</vuln:product>
      <vuln:product>cpe:/a:digium:asterisk:1.2.8</vuln:product>
      <vuln:product>cpe:/a:digium:asterisk:1.2.9</vuln:product>
      <vuln:product>cpe:/a:digium:asterisk:1.2.10</vuln:product>
      <vuln:product>cpe:/a:digium:asterisk:1.2.11</vuln:product>
      <vuln:product>cpe:/a:digium:asterisk:1.2.12</vuln:product>
      <vuln:product>cpe:/a:digium:asterisk:1.2.12.1</vuln:product>
      <vuln:product>cpe:/a:digium:asterisk:1.2.13</vuln:product>
      <vuln:product>cpe:/a:digium:asterisk:1.2.14</vuln:product>
      <vuln:product>cpe:/a:digium:asterisk:1.2.15</vuln:product>
      <vuln:product>cpe:/a:digium:asterisk:1.2_beta1</vuln:product>
      <vuln:product>cpe:/a:digium:asterisk:1.2_beta2</vuln:product>
      <vuln:product>cpe:/a:digium:asterisk:1.4.0</vuln:product>
      <vuln:product>cpe:/a:digium:asterisk:1.4.0_beta1</vuln:product>
      <vuln:product>cpe:/a:digium:asterisk:1.4.0_beta2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1306</vuln:cve-id>
    <vuln:published-datetime>2007-03-06T19:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:43.953-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://asterisk.org/node/48319" xml:lang="en">http://asterisk.org/node/48319</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://asterisk.org/node/48320" xml:lang="en">http://asterisk.org/node/48320</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://labs.musecurity.com/advisories/MU-200703-01.txt" xml:lang="en">http://labs.musecurity.com/advisories/MU-200703-01.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200703-14.xml" xml:lang="en">GLSA-200703-14</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1358" xml:lang="en">DSA-1358</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/228032" xml:lang="en">VU#228032</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_34_asterisk.html" xml:lang="en">SUSE-SA:2007:034</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22838" xml:lang="en">22838</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017723" xml:lang="en">1017723</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0830" xml:lang="en">ADV-2007-0830</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32830" xml:lang="en">asterisk-sip-channeldriver-dos(32830)</vuln:reference>
    </vuln:references>
    <vuln:summary>Asterisk 1.4 before 1.4.1 and 1.2 before 1.2.16 allows remote attackers to cause a denial of service (crash) by sending a Session Initiation Protocol (SIP) packet without a URI and SIP-version header, which results in a NULL pointer dereference.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1307">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:intel:pro_1000_lan_adapter:135400"/>
        <cpe-lang:fact-ref name="cpe:/h:lenovo:thinkpad:r50"/>
        <cpe-lang:fact-ref name="cpe:/h:lenovo:thinkpad:r50e"/>
        <cpe-lang:fact-ref name="cpe:/h:lenovo:thinkpad:r50p"/>
        <cpe-lang:fact-ref name="cpe:/h:lenovo:thinkpad:r51"/>
        <cpe-lang:fact-ref name="cpe:/h:lenovo:thinkpad:t41"/>
        <cpe-lang:fact-ref name="cpe:/h:lenovo:thinkpad:t41p"/>
        <cpe-lang:fact-ref name="cpe:/h:lenovo:thinkpad:t42"/>
        <cpe-lang:fact-ref name="cpe:/h:lenovo:thinkpad:t42p"/>
        <cpe-lang:fact-ref name="cpe:/h:lenovo:thinkpad:t60"/>
        <cpe-lang:fact-ref name="cpe:/h:lenovo:thinkpad:t60p"/>
        <cpe-lang:fact-ref name="cpe:/h:lenovo:thinkpad:x31"/>
        <cpe-lang:fact-ref name="cpe:/h:lenovo:thinkpad:x32"/>
        <cpe-lang:fact-ref name="cpe:/h:lenovo:thinkpad:x40"/>
        <cpe-lang:fact-ref name="cpe:/h:lenovo:thinkpad:x60"/>
        <cpe-lang:fact-ref name="cpe:/h:lenovo:thinkpad:x60_tablet"/>
        <cpe-lang:fact-ref name="cpe:/h:lenovo:thinkpad:x60s"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:intel:pro_1000_lan_adapter:135400</vuln:product>
      <vuln:product>cpe:/h:lenovo:thinkpad:r50</vuln:product>
      <vuln:product>cpe:/h:lenovo:thinkpad:r50e</vuln:product>
      <vuln:product>cpe:/h:lenovo:thinkpad:r50p</vuln:product>
      <vuln:product>cpe:/h:lenovo:thinkpad:r51</vuln:product>
      <vuln:product>cpe:/h:lenovo:thinkpad:t41</vuln:product>
      <vuln:product>cpe:/h:lenovo:thinkpad:t41p</vuln:product>
      <vuln:product>cpe:/h:lenovo:thinkpad:t42</vuln:product>
      <vuln:product>cpe:/h:lenovo:thinkpad:t42p</vuln:product>
      <vuln:product>cpe:/h:lenovo:thinkpad:t60</vuln:product>
      <vuln:product>cpe:/h:lenovo:thinkpad:t60p</vuln:product>
      <vuln:product>cpe:/h:lenovo:thinkpad:x31</vuln:product>
      <vuln:product>cpe:/h:lenovo:thinkpad:x32</vuln:product>
      <vuln:product>cpe:/h:lenovo:thinkpad:x40</vuln:product>
      <vuln:product>cpe:/h:lenovo:thinkpad:x60</vuln:product>
      <vuln:product>cpe:/h:lenovo:thinkpad:x60_tablet</vuln:product>
      <vuln:product>cpe:/h:lenovo:thinkpad:x60s</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1307</vuln:cve-id>
    <vuln:published-datetime>2007-03-06T19:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:51:43.033-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22822" xml:lang="en">22822</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0801" xml:lang="en">ADV-2007-0801</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www-307.ibm.com/pc/support/site.wss/document.do?sitestyle=lenovo&amp;lndocid=MIGR-62922" xml:lang="en">http://www-307.ibm.com/pc/support/site.wss/document.do?sitestyle=lenovo&amp;lndocid=MIGR-62922</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in Lenovo Intel PRO/1000 LAN adapter before Build 135400, as used on IBM Lenovo ThinkPad systems, has unknown impact and attack vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1308">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:kde:konqueror:3.5.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:kde:konqueror:3.5.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1308</vuln:cve-id>
    <vuln:published-datetime>2007-03-06T19:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:54.720-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10551" name="oval:org.mitre.oval:def:10551"/>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://bindshell.net/advisories/konq355" xml:lang="en">http://bindshell.net/advisories/konq355</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://bindshell.net/advisories/konq355/konq355-patch.diff" xml:lang="en">http://bindshell.net/advisories/konq355/konq355-patch.diff</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-March/052793.html" xml:lang="en">20070304 Konqueror DoS Via JavaScript Read Of FTP Iframe</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2345" xml:lang="en">2345</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:054" xml:lang="en">MDKSA-2007:054</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0909.html" xml:lang="en">RHSA-2007:0909</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461897/100/0/threaded" xml:lang="en">20070304 Konqueror DoS Via JavaScript Read Of FTP Iframe</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22814" xml:lang="en">22814</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-447-1" xml:lang="en">USN-447-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0886" xml:lang="en">ADV-2007-0886</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32798" xml:lang="en">konqueror-ftp-dos(32798)</vuln:reference>
    </vuln:references>
    <vuln:summary>ecma/kjs_html.cpp in KDE JavaScript (KJS), as used in Konqueror in KDE 3.5.5, allows remote attackers to cause a denial of service (crash) by accessing the content of an iframe with an ftp:// URI in the src attribute, probably due to a NULL pointer dereference.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1309">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:novell:access_manager:3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:novell:access_manager:3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1309</vuln:cve-id>
    <vuln:published-datetime>2007-03-06T19:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:51:43.377-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-264"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017722" xml:lang="en">1017722</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0800" xml:lang="en">ADV-2007-0800</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://secure-support.novell.com/KanisaPlatform/Publishing/648/3429077_f.SAL_Public.html" xml:lang="en">https://secure-support.novell.com/KanisaPlatform/Publishing/648/3429077_f.SAL_Public.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Novell Access Management 3 SSLVPN Server allows remote authenticated users to bypass VPN restrictions by making policy.txt read-only, disconnecting, then manually modifying policy.txt.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1313">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:netxautomation:netxeib:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:netxautomation:netxeib:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1313</vuln:cve-id>
    <vuln:published-datetime>2007-03-21T15:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:55.657-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/296593" xml:lang="en">VU#296593</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/MIMG-6XEPXN" xml:lang="en">http://www.kb.cert.org/vuls/id/MIMG-6XEPXN</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.neutralbit.com/advisories/NB07-22.txt" xml:lang="en">http://www.neutralbit.com/advisories/NB07-22.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/463539/100/0/threaded" xml:lang="en">20070322 [NB07-22] Multiple vulnerabilities in NETxEIB OPC server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23059" xml:lang="en">23059</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017803" xml:lang="en">1017803</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1038" xml:lang="en">ADV-2007-1038</vuln:reference>
    </vuln:references>
    <vuln:summary>NETxAutomation NETxEIB OPC Server before 3.0.1300 does not properly validate OLE for Process Control (OPC) server handles, which allows attackers to cause a denial of service or possibly execute arbitrary code via unspecified vectors involving the (1) IOPCSyncIO::Read, (2) IOPCSyncIO::Write, (3) IOPCServer::AddGroup, (4) IOPCServer::RemoveGroup, (5) IOPCCommon::SetClientName, and (6) IOPCGroupStateMgt::CloneGroup functions, which allow access to arbitrary memory. NOTE: the vectors might be limited to attackers with physical access.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1319">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:takebishi_corporation:devicexplorer_opc_server:3.12_build1"/>
        <cpe-lang:fact-ref name="cpe:/a:takebishi_corporation:devicexplorer_opc_server:3.12_build2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:takebishi_corporation:devicexplorer_opc_server:3.12_build1</vuln:product>
      <vuln:product>cpe:/a:takebishi_corporation:devicexplorer_opc_server:3.12_build2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1319</vuln:cve-id>
    <vuln:published-datetime>2007-03-19T18:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:56.250-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.faweb.net/us/opc/1231207.html" xml:lang="en">http://www.faweb.net/us/opc/1231207.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/926551" xml:lang="en">VU#926551</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.neutralbit.com/advisories/NB07-07.txt" xml:lang="en">http://www.neutralbit.com/advisories/NB07-07.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.neutralbit.com/advisories/NB07-08.txt" xml:lang="en">http://www.neutralbit.com/advisories/NB07-08.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.neutralbit.com/advisories/NB07-09.txt" xml:lang="en">http://www.neutralbit.com/advisories/NB07-09.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.neutralbit.com/advisories/NB07-10.txt" xml:lang="en">http://www.neutralbit.com/advisories/NB07-10.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.neutralbit.com/advisories/NB07-17.txt" xml:lang="en">http://www.neutralbit.com/advisories/NB07-17.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/463537/100/0/threaded" xml:lang="en">20070322 [NB07-17] Multiple vulnerabilities in Takebishi Electric DeviceXplorer SYSMAC OPC server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/463546/100/0/threaded" xml:lang="en">20070322 [NB07-07] Multiple vulnerabilities in Takebishi Electric DeviceXplorer HIDIC OPC server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/463550/100/0/threaded" xml:lang="en">20070322 [NB07-08] Multiple vulnerabilities in Takebishi Electric DeviceXplorer MELSEC OPC server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/463556/100/0/threaded" xml:lang="en">20070322 [NB07-09] Multiple vulnerabilities in Takebishi Electric DeviceXplorer FA-M3 OPC server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/463559/100/0/threaded" xml:lang="en">20070322 [NB07-10] Multiple vulnerabilities in Takebishi Electric DeviceXplorer MODBUS OPC server</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23037" xml:lang="en">23037</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017793" xml:lang="en">1017793</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1029" xml:lang="en">ADV-2007-1029</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in the IOPCServer::RemoveGroup function in the OPCDA interface in Takebishi Electric DeviceXPlorer OLE for Process Control (OPC) Server before 3.12 Build3 allows remote attackers to execute arbitrary code via unspecified vectors involving access to arbitrary memory. NOTE: this issue affects the (1) HIDIC, (2) MELSEC, (3) FA-M3, (4) MODBUS, and (5) SYSMAC OPC Servers.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1320">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:fabrice_bellard:qemu:0.8.2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:xen:xen"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:fabrice_bellard:qemu:0.8.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1320</vuln:cve-id>
    <vuln:published-datetime>2007-05-02T13:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:49.470-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10315" name="oval:org.mitre.oval:def:10315"/>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00004.html" xml:lang="en">SUSE-SR:2009:002</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://taviso.decsystem.org/virtsec.pdf" xml:lang="en">http://taviso.decsystem.org/virtsec.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1284" xml:lang="en">DSA-1284</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1384" xml:lang="en">DSA-1384</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:203" xml:lang="en">MDKSA-2007:203</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:162" xml:lang="en">MDVSA-2008:162</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0323.html" xml:lang="en">RHSA-2007:0323</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23731" xml:lang="en">23731</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1597" xml:lang="en">ADV-2007-1597</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00082.html" xml:lang="en">FEDORA-2007-713</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00706.html" xml:lang="en">FEDORA-2008-4386</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00935.html" xml:lang="en">FEDORA-2008-4604</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple heap-based buffer overflows in the cirrus_invalidate_region function in the Cirrus VGA extension in QEMU 0.8.2, as used in Xen and possibly other products, might allow local users to execute arbitrary code via unspecified vectors related to "attempting to mark non-existent regions as dirty," aka the "bitblt" heap overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1321">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:fabrice_bellard:qemu:0.8.2"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:xen:xen"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:fabrice_bellard:qemu:0.8.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1321</vuln:cve-id>
    <vuln:published-datetime>2007-10-30T18:46:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:49.550-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9302" name="oval:org.mitre.oval:def:9302"/>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1018761" xml:lang="en">1018761</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://taviso.decsystem.org/virtsec.pdf" xml:lang="en">http://taviso.decsystem.org/virtsec.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VIM</vuln:source>
      <vuln:reference href="http://www.attrition.org/pipermail/vim/2007-October/001842.html" xml:lang="en">20071030 Clarification on old QEMU/NE2000/Xen issues</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1284" xml:lang="en">DSA-1284</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:203" xml:lang="en">MDKSA-2007:203</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:162" xml:lang="en">MDVSA-2008:162</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0323.html" xml:lang="en">RHSA-2007:0323</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23731" xml:lang="en">23731</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1597" xml:lang="en">ADV-2007-1597</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00004.html" xml:lang="en">FEDORA-2007-2708</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00030.html" xml:lang="en">FEDORA-2007-2270</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FEDORA</vuln:source>
      <vuln:reference href="https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00082.html" xml:lang="en">FEDORA-2007-713</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to trigger a heap-based buffer overflow via certain register values that bypass sanity checks, aka QEMU NE2000 "receive" integer signedness error. NOTE: this identifier was inadvertently used by some sources to cover multiple issues that were labeled "NE2000 network driver and the socket code," but separate identifiers have been created for the individual vulnerabilities since there are sometimes different fixes; see CVE-2007-5729 and CVE-2007-5730.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1322">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:fabrice_bellard:qemu:0.8.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:fabrice_bellard:qemu:0.8.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1322</vuln:cve-id>
    <vuln:published-datetime>2007-05-02T13:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:44.080-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://taviso.decsystem.org/virtsec.pdf" xml:lang="en">http://taviso.decsystem.org/virtsec.pdf</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1284" xml:lang="en">DSA-1284</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDVSA-2008:162" xml:lang="en">MDVSA-2008:162</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23731" xml:lang="en">23731</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1597" xml:lang="en">ADV-2007-1597</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/34043" xml:lang="en">qemu-icebp-dos(34043)</vuln:reference>
    </vuln:references>
    <vuln:summary>QEMU 0.8.2 allows local users to halt a virtual machine by executing the icebp instruction.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1323">
    <vuln:cve-id>CVE-2007-1323</vuln:cve-id>
    <vuln:published-datetime>2007-10-30T17:46:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-10T20:51:00.367-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2007-2893.  Reason: this candidate was intended for one issue, but some sources used this identifier for a separate issue, and a duplicate identifier had also been created by the time dual use was detected.  Notes: All CVE users should consult CVE-2007-2893 to determine if it is appropriate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1324">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:snapgear:560:1.7.8_firmware"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:560:1.7.9_firmware"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:560:1.7.10_firmware"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:560:1.8.4_firmware"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:560:1.8.5_firmware"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:560:1.8_firmware"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:560:3.1.4u2"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:580:1.7.8_firmware"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:580:1.7.9_firmware"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:580:1.7.10_firmware"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:580:1.8.4_firmware"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:580:1.8.5_firmware"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:580:1.8_firmware"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:580:3.1.4u2_firmware"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:585:1.7.8_firmware"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:585:1.7.9_firmware"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:585:1.7.10_firmware"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:585:1.8.4_firmware"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:585:1.8.5_firmware"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:585:1.8_firmware"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:585:3.1.4u2_firmware"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:640:1.7.8_firmware"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:640:1.7.9_firmware"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:640:1.7.10_firmware"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:640:1.8.4_firmware"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:640:1.8.5_firmware"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:640:1.8_firmware"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:640:3.1.4u2_firmware"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:710:1.7.8_firmware"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:710:1.7.9_firmware"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:710:1.7.10_firmware"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:710:1.8.4_firmware"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:710:1.8.5_firmware"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:710:1.8_firmware"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:710:3.1.4u2_firmware"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:720:1.7.8_firmware"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:720:1.7.9_firmware"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:720:1.7.10_firmware"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:720:1.8.4_firmware"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:720:1.8.5_firmware"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:720:1.8_firmware"/>
        <cpe-lang:fact-ref name="cpe:/h:snapgear:720:3.1.4u2_firmware"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:snapgear:560:1.7.8_firmware</vuln:product>
      <vuln:product>cpe:/h:snapgear:560:1.7.9_firmware</vuln:product>
      <vuln:product>cpe:/h:snapgear:560:1.7.10_firmware</vuln:product>
      <vuln:product>cpe:/h:snapgear:560:1.8.4_firmware</vuln:product>
      <vuln:product>cpe:/h:snapgear:560:1.8.5_firmware</vuln:product>
      <vuln:product>cpe:/h:snapgear:560:1.8_firmware</vuln:product>
      <vuln:product>cpe:/h:snapgear:560:3.1.4u2</vuln:product>
      <vuln:product>cpe:/h:snapgear:580:1.7.8_firmware</vuln:product>
      <vuln:product>cpe:/h:snapgear:580:1.7.9_firmware</vuln:product>
      <vuln:product>cpe:/h:snapgear:580:1.7.10_firmware</vuln:product>
      <vuln:product>cpe:/h:snapgear:580:1.8.4_firmware</vuln:product>
      <vuln:product>cpe:/h:snapgear:580:1.8.5_firmware</vuln:product>
      <vuln:product>cpe:/h:snapgear:580:1.8_firmware</vuln:product>
      <vuln:product>cpe:/h:snapgear:580:3.1.4u2_firmware</vuln:product>
      <vuln:product>cpe:/h:snapgear:585:1.7.8_firmware</vuln:product>
      <vuln:product>cpe:/h:snapgear:585:1.7.9_firmware</vuln:product>
      <vuln:product>cpe:/h:snapgear:585:1.7.10_firmware</vuln:product>
      <vuln:product>cpe:/h:snapgear:585:1.8.4_firmware</vuln:product>
      <vuln:product>cpe:/h:snapgear:585:1.8.5_firmware</vuln:product>
      <vuln:product>cpe:/h:snapgear:585:1.8_firmware</vuln:product>
      <vuln:product>cpe:/h:snapgear:585:3.1.4u2_firmware</vuln:product>
      <vuln:product>cpe:/h:snapgear:640:1.7.8_firmware</vuln:product>
      <vuln:product>cpe:/h:snapgear:640:1.7.9_firmware</vuln:product>
      <vuln:product>cpe:/h:snapgear:640:1.7.10_firmware</vuln:product>
      <vuln:product>cpe:/h:snapgear:640:1.8.4_firmware</vuln:product>
      <vuln:product>cpe:/h:snapgear:640:1.8.5_firmware</vuln:product>
      <vuln:product>cpe:/h:snapgear:640:1.8_firmware</vuln:product>
      <vuln:product>cpe:/h:snapgear:640:3.1.4u2_firmware</vuln:product>
      <vuln:product>cpe:/h:snapgear:710:1.7.8_firmware</vuln:product>
      <vuln:product>cpe:/h:snapgear:710:1.7.9_firmware</vuln:product>
      <vuln:product>cpe:/h:snapgear:710:1.7.10_firmware</vuln:product>
      <vuln:product>cpe:/h:snapgear:710:1.8.4_firmware</vuln:product>
      <vuln:product>cpe:/h:snapgear:710:1.8.5_firmware</vuln:product>
      <vuln:product>cpe:/h:snapgear:710:1.8_firmware</vuln:product>
      <vuln:product>cpe:/h:snapgear:710:3.1.4u2_firmware</vuln:product>
      <vuln:product>cpe:/h:snapgear:720:1.7.8_firmware</vuln:product>
      <vuln:product>cpe:/h:snapgear:720:1.7.9_firmware</vuln:product>
      <vuln:product>cpe:/h:snapgear:720:1.7.10_firmware</vuln:product>
      <vuln:product>cpe:/h:snapgear:720:1.8.4_firmware</vuln:product>
      <vuln:product>cpe:/h:snapgear:720:1.8.5_firmware</vuln:product>
      <vuln:product>cpe:/h:snapgear:720:1.8_firmware</vuln:product>
      <vuln:product>cpe:/h:snapgear:720:3.1.4u2_firmware</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1324</vuln:cve-id>
    <vuln:published-datetime>2007-03-07T16:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:44.140-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.cyberguard.info/snapgear/releases.html" xml:lang="en">http://www.cyberguard.info/snapgear/releases.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22835" xml:lang="en">22835</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0850" xml:lang="en">ADV-2007-0850</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32824" xml:lang="en">snapgear-packet-dos(32824)</vuln:reference>
    </vuln:references>
    <vuln:summary>SnapGear 560, 585, 580, 640, 710, and 720 appliances before the 3.1.4u5 firmware allow remote attackers to cause a denial of service (complete packet loss) via a packet flood, a different vulnerability than CVE-2006-4613.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1325">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:phpmyadmin:phpmyadmin:2.10.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:phpmyadmin:phpmyadmin:2.10.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1325</vuln:cve-id>
    <vuln:published-datetime>2007-03-07T16:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:51:56.393-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1671813&amp;group_id=23067&amp;atid=377408" xml:lang="en">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1671813&amp;group_id=23067&amp;atid=377408</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:199" xml:lang="en">MDKSA-2007:199</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.php.net/ChangeLog-4.php" xml:lang="en">http://www.php.net/ChangeLog-4.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.php.net/releases/4_4_8.php" xml:lang="en">http://www.php.net/releases/4_4_8.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2007-3" xml:lang="en">http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2007-3</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.php-security.org/MOPB/MOPB-02-2007.html" xml:lang="en">http://www.php-security.org/MOPB/MOPB-02-2007.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22841" xml:lang="en">22841</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.us.debian.org/security/2007/dsa-1370" xml:lang="en">DSA-1370</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0831" xml:lang="en">ADV-2007-0831</vuln:reference>
    </vuln:references>
    <vuln:summary>The PMA_ArrayWalkRecursive function in libraries/common.lib.php in phpMyAdmin before 2.10.0.2 does not limit recursion on arrays provided by users, which allows context-dependent attackers to cause a denial of service (web server crash) via an array with many dimensions.  NOTE: it could be argued that this vulnerability is caused by a problem in PHP (CVE-2006-1549) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in phpMyAdmin.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1326">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:serendipity:serendipity:1.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:serendipity:serendipity:1.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1326</vuln:cve-id>
    <vuln:published-datetime>2007-03-07T16:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:57.547-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2383" xml:lang="en">2383</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461671/100/0/threaded" xml:lang="en">20070301 Serendipity unauthenticated SQL-Injection</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32768" xml:lang="en">serendipity-index-sql-injection(32768)</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in index.php in Serendipity 1.1.1 allows remote attackers to execute arbitrary SQL commands via the serendipity[multiCat][] parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1327">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:silc:silc-server:1.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:silc:silc-server:1.0.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1327</vuln:cve-id>
    <vuln:published-datetime>2007-03-07T16:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:44.267-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-476"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>FULLDISC</vuln:source>
      <vuln:reference href="http://marc.info/?l=full-disclosure&amp;m=117320823618036&amp;w=2" xml:lang="en">20070306 silc-server 1.0.2 denial-of-service vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200703-12.xml" xml:lang="en">GLSA-200703-12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22846" xml:lang="en">22846</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32846" xml:lang="en">silc-command-dos(32846)</vuln:reference>
    </vuln:references>
    <vuln:summary>The SILC_SERVER_CMD_FUNC function in apps/silcd/command.c in silc-server 1.0.2 allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via a request without a cipher algorithm and an invalid HMAC algorithm.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1328">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:bernard_joly:bj_webring"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bernard_joly:bj_webring</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1328</vuln:cve-id>
    <vuln:published-datetime>2007-03-07T16:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:57.797-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://forums.avenir-geopolitique.net/viewtopic.php?t=2707" xml:lang="en">http://forums.avenir-geopolitique.net/viewtopic.php?t=2707</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2384" xml:lang="en">2384</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461802/100/0/threaded" xml:lang="en">20070303 BJ Webring XSS</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in formulaire.php in Bernard JOLY BJ Webring allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter related to the add link menu.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1329">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ledgersmb:ledgersmb:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sql-ledger:sql-ledger:2.6.25"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ledgersmb:ledgersmb:1.1.1</vuln:product>
      <vuln:product>cpe:/a:sql-ledger:sql-ledger:2.6.25</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1329</vuln:cve-id>
    <vuln:published-datetime>2007-03-07T16:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:57.987-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2381" xml:lang="en">2381</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://securitytracker.com/id?1017715" xml:lang="en">1017715</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461630/100/0/threaded" xml:lang="en">20070301 Full disclosure: Directory Transversal and Arbitrary Code Execution Vulnerability in SQL-Ledger and LedgerSMB</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32776" xml:lang="en">sqlledger-userpathmemberfile-dir-traversal(32776)</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in SQL-Ledger, and LedgerSMB before 1.1.5, allows remote attackers to read and overwrite arbitrary files, and execute arbitrary code, via . (dot) characters adjacent to (1) users and (2) users/members strings, which are removed by blacklisting functions that filter these strings and collapse into .. (dot dot) sequences.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1330">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:comodo:comodo_firewall_pro:2.4.16.174"/>
        <cpe-lang:fact-ref name="cpe:/a:comodo:comodo_firewall_pro:2.4.17.183"/>
        <cpe-lang:fact-ref name="cpe:/a:comodo:comodo_firewall_pro:2.4.18.184"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:comodo:comodo_firewall_pro:2.4.16.174</vuln:product>
      <vuln:product>cpe:/a:comodo:comodo_firewall_pro:2.4.17.183</vuln:product>
      <vuln:product>cpe:/a:comodo:comodo_firewall_pro:2.4.18.184</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1330</vuln:cve-id>
    <vuln:published-datetime>2007-03-07T16:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:58.533-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.4</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2388" xml:lang="en">2388</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.matousec.com/info/advisories/Comodo-Bypassing-settings-protection-using-magic-pipe.php" xml:lang="en">http://www.matousec.com/info/advisories/Comodo-Bypassing-settings-protection-using-magic-pipe.php</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461635/100/0/threaded" xml:lang="en">20070301 Comodo Bypassing settings protection using magic pipe Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22775" xml:lang="en">22775</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32771" xml:lang="en">comodofirewallpro-pipe-security-bypass(32771)</vuln:reference>
    </vuln:references>
    <vuln:summary>Comodo Firewall Pro (CFP) (formerly Comodo Personal Firewall) 2.4.18.184 and earlier allows local users to bypass driver protections on the HKLM\SYSTEM\Software\Comodo\Personal Firewall registry key by guessing the name of a named pipe under \Device\NamedPipe\OLE and attempting to open it multiple times.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1331">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:tks_banking_solutions:eportfolio:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:tks_banking_solutions:eportfolio:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1331</vuln:cve-id>
    <vuln:published-datetime>2007-03-07T16:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:58.957-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2385" xml:lang="en">2385</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.scip.ch/cgi-bin/smss/showadvf.pl?id=2893" xml:lang="en">http://www.scip.ch/cgi-bin/smss/showadvf.pl?id=2893</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.scip.ch/publikationen/advisories/scip_advisory-2893_eportfolio_%201.0_java_multiple_vulnerabilities.txt" xml:lang="en">http://www.scip.ch/publikationen/advisories/scip_advisory-2893_eportfolio_%201.0_java_multiple_vulnerabilities.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461895/100/0/threaded" xml:lang="en">20070305 ePortfolio version 1.0 Java Multiple Input Validation Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22829" xml:lang="en">22829</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site scripting (XSS) vulnerabilities in TKS Banking Solutions ePortfolio 1.0 Java allow remote attackers to inject arbitrary web script or HTML via unspecified vectors that bypass the client-side protection scheme, one of which may be the q parameter to the search program.  NOTE: some of these details are obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1332">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:tks_banking_solutions:eportfolio:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:tks_banking_solutions:eportfolio:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1332</vuln:cve-id>
    <vuln:published-datetime>2007-03-07T16:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:59.313-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2385" xml:lang="en">2385</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.scip.ch/cgi-bin/smss/showadvf.pl?id=2893" xml:lang="en">http://www.scip.ch/cgi-bin/smss/showadvf.pl?id=2893</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.scip.ch/publikationen/advisories/scip_advisory-2893_eportfolio_%201.0_java_multiple_vulnerabilities.txt" xml:lang="en">http://www.scip.ch/publikationen/advisories/scip_advisory-2893_eportfolio_%201.0_java_multiple_vulnerabilities.txt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461895/100/0/threaded" xml:lang="en">20070305 ePortfolio version 1.0 Java Multiple Input Validation Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22829" xml:lang="en">22829</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple cross-site request forgery (CSRF) vulnerabilities in TKS Banking Solutions ePortfolio 1.0 Java allow remote attackers to perform unspecified restricted actions in the context of certain accounts by bypassing the client-side protection scheme.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1337">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:vmware:workstation:5.5.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:vmware:workstation:5.5.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1337</vuln:cve-id>
    <vuln:published-datetime>2007-05-02T15:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:37:59.657-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/467936/30/6690/threaded" xml:lang="en">20070507 VMSA-2007-0004 Multiple Denial-of-Service issues fixed</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/469011/30/6510/threaded" xml:lang="en">20070518 VMSA-2007-0004.1 Updated: Multiple Denial-of-Service issues fixed and directory traversal vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23732" xml:lang="en">23732</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018011" xml:lang="en">1018011</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html#554" xml:lang="en">http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html#554</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1592" xml:lang="en">ADV-2007-1592</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33990" xml:lang="en">vmware-acpi-unspecified(33990)</vuln:reference>
    </vuln:references>
    <vuln:summary>The virtual machine process (VMX) in VMware Workstation before 5.5.4 does not properly read state information when moving from the ACPI sleep state to the run state, which allows attackers to cause a denial of service (virtual machine reboot) via unknown vectors.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1338">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:apple:airport_extreme:7.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:apple:airport_extreme:7.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1338</vuln:cve-id>
    <vuln:published-datetime>2007-03-08T17:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:44.487-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://arstechnica.com/journals/apple.ars/2007/2/14/7063" xml:lang="en">http://arstechnica.com/journals/apple.ars/2007/2/14/7063</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://docs.info.apple.com/article.html?artnum=305366" xml:lang="en">http://docs.info.apple.com/article.html?artnum=305366</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2007/Apr/msg00000.html" xml:lang="en">APPLE-SA-2007-04-09</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017889" xml:lang="en">1017889</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1308" xml:lang="en">ADV-2007-1308</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33526" xml:lang="en">airportextreme-ipv6-security-bypass(33526)</vuln:reference>
    </vuln:references>
    <vuln:summary>The default configuration of the AirPort utility in Apple AirPort Extreme creates an IPv6 tunnel but does not enable the "Block incoming IPv6 connections" setting, which might allow remote attackers to bypass intended access restrictions by establishing IPv6 sessions that would have been rejected over IPv4.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1339">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:monitor-line:links_management:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:monitor-line:links_management:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1339</vuln:cve-id>
    <vuln:published-datetime>2007-03-08T17:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-18T21:30:07.143-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22825" xml:lang="en">22825</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0849" xml:lang="en">ADV-2007-0849</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32813" xml:lang="en">links-index-sql-injection(32813)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3416" xml:lang="en">3416</vuln:reference>
    </vuln:references>
    <vuln:summary>SQL injection vulnerability in index.php in Links Management Application 1.0 allows remote attackers to execute arbitrary SQL commands via the lcnt parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1340">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:weltennetz:news-letterman:1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:weltennetz:news-letterman:1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1340</vuln:cve-id>
    <vuln:published-datetime>2007-03-08T17:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:49.597-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22807" xml:lang="en">22807</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32787" xml:lang="en">newsletterman-eintrag-file-include(32787)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3406" xml:lang="en">3406</vuln:reference>
    </vuln:references>
    <vuln:summary>PHP remote file inclusion vulnerability in eintrag.php in Weltennetz News-Letterman 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the sqllog parameter.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1341">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:simple_invoices:simple_invoices:2006-12-11"/>
        <cpe-lang:fact-ref name="cpe:/a:simple_invoices:simple_invoices:2007-01-25"/>
        <cpe-lang:fact-ref name="cpe:/a:simple_invoices:simple_invoices:2007-02-02"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:simple_invoices:simple_invoices:2006-12-11</vuln:product>
      <vuln:product>cpe:/a:simple_invoices:simple_invoices:2007-01-25</vuln:product>
      <vuln:product>cpe:/a:simple_invoices:simple_invoices:2007-02-02</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1341</vuln:cve-id>
    <vuln:published-datetime>2007-03-08T17:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-13T01:34:40.083-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://code.google.com/p/simpleinvoices/issues/detail?id=35" xml:lang="en">http://code.google.com/p/simpleinvoices/issues/detail?id=35</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://forum.tufat.com/showthread.php?p=116753#post116753" xml:lang="en">http://forum.tufat.com/showthread.php?p=116753#post116753</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22818" xml:lang="en">22818</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://sourceforge.net/project/shownotes.php?group_id=164303&amp;release_id=491300" xml:lang="en">https://sourceforge.net/project/shownotes.php?group_id=164303&amp;release_id=491300</vuln:reference>
    </vuln:references>
    <vuln:summary>include/auth/auth.php in Simple Invoices before 2007 03 05 does not use the login system to protect print preview pages for invoices, which might allow attackers to obtain sensitive information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1342">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:jelsoft:vbulletin:3.6.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:jelsoft:vbulletin:3.6.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1342</vuln:cve-id>
    <vuln:published-datetime>2007-03-08T17:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:38:00.347-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2396" xml:lang="en">2396</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/461727/100/0/threaded" xml:lang="en">20070302 vBulletin v3.6.5 admincp/index.php ( rss feed ) xss vuln.</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22790" xml:lang="en">22790</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32780" xml:lang="en">vbulletin-admincpindex-xss(32780)</vuln:reference>
    </vuln:references>
    <vuln:summary>Cross-site scripting (XSS) vulnerability in admincp/index.php in Jelsoft vBulletin 3.6.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the add rss url form.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1343">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:webcalendar:webcalendar:1.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:webcalendar:webcalendar:1.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:webcalendar:webcalendar:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:webcalendar:webcalendar:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:webcalendar:webcalendar:1.0.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:webcalendar:webcalendar:1.0.0</vuln:product>
      <vuln:product>cpe:/a:webcalendar:webcalendar:1.0.1</vuln:product>
      <vuln:product>cpe:/a:webcalendar:webcalendar:1.0.2</vuln:product>
      <vuln:product>cpe:/a:webcalendar:webcalendar:1.0.3</vuln:product>
      <vuln:product>cpe:/a:webcalendar:webcalendar:1.0.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1343</vuln:cve-id>
    <vuln:published-datetime>2007-03-08T17:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:44.687-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://sourceforge.net/mailarchive/forum.php?thread_id=31840112&amp;forum_id=46247" xml:lang="en">[webcalendar-announce] 20070304 Announce: Release 1.0.5 (security patch)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?group_id=3870&amp;release_id=491130" xml:lang="en">http://sourceforge.net/project/shownotes.php?group_id=3870&amp;release_id=491130</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://webcalendar.cvs.sourceforge.net/webcalendar/webcalendar/includes/functions.php?r1=1.211.2.7&amp;r2=1.211.2.8" xml:lang="en">http://webcalendar.cvs.sourceforge.net/webcalendar/webcalendar/includes/functions.php?r1=1.211.2.7&amp;r2=1.211.2.8</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://webcalendar.cvs.sourceforge.net/webcalendar/webcalendar/includes/functions.php?view=log" xml:lang="en">http://webcalendar.cvs.sourceforge.net/webcalendar/webcalendar/includes/functions.php?view=log</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1267" xml:lang="en">DSA-1267</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22834" xml:lang="en">22834</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0851" xml:lang="en">ADV-2007-0851</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32832" xml:lang="en">webcalendar-noset-variable-overwrite(32832)</vuln:reference>
    </vuln:references>
    <vuln:summary>includes/functions.php in Craig Knudsen WebCalendar before 1.0.5 does not protect the noSet variable from external modification, which allows remote attackers to set arbitrary global variables via a URL with modified values in the noSet parameter, which leads to resultant vulnerabilities that probably include remote file inclusion and other issues.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1344">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:icecast:ezstream:0.1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:icecast:ezstream:0.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:icecast:ezstream:0.1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:icecast:ezstream:0.1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:icecast:ezstream:0.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:icecast:ezstream:0.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:icecast:ezstream:0.1.0</vuln:product>
      <vuln:product>cpe:/a:icecast:ezstream:0.1.1</vuln:product>
      <vuln:product>cpe:/a:icecast:ezstream:0.1.2</vuln:product>
      <vuln:product>cpe:/a:icecast:ezstream:0.1.3</vuln:product>
      <vuln:product>cpe:/a:icecast:ezstream:0.2.0</vuln:product>
      <vuln:product>cpe:/a:icecast:ezstream:0.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1344</vuln:cve-id>
    <vuln:published-datetime>2007-03-08T17:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-07-28T21:30:44.737-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.icecast.org/ezstream.php#ez_relnotes" xml:lang="en">http://www.icecast.org/ezstream.php#ez_relnotes</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22840" xml:lang="en">22840</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0852" xml:lang="en">ADV-2007-0852</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32867" xml:lang="en">ezstream-replacestring-urlparse-bo(32867)</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in src/ezstream.c in Ezstream before 0.3.0 allow remote attackers to execute arbitrary code via a crafted XML configuration file processed by the (1) urlParse function, which causes a stack-based overflow and the (2) ReplaceString function, which causes a heap-based overflow.  NOTE: some of these details are obtained from third party information.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1345">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:ca:etrust_admin:8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:etrust_admin:8.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ca:etrust_admin:8.1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ca:etrust_admin:8.1</vuln:product>
      <vuln:product>cpe:/a:ca:etrust_admin:8.1.1</vuln:product>
      <vuln:product>cpe:/a:ca:etrust_admin:8.1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1345</vuln:cve-id>
    <vuln:published-datetime>2007-03-10T14:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:38:00.643-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2404" xml:lang="en">2404</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/462312/100/0/threaded" xml:lang="en">20070309 [CAID 35145]: CA eTrust Admin Privilege Escalation Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22885" xml:lang="en">22885</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017740" xml:lang="en">1017740</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0885" xml:lang="en">ADV-2007-0885</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=35145" xml:lang="en">http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=35145</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32887" xml:lang="en">ca-etrust-admin-authentication-bypass(32887)</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in cube.exe in the GINA component for CA (Computer Associates) eTrust Admin 8.1.0 through 8.1.2 allows attackers with physical interactive or Remote Desktop access to bypass authentication and gain privileges via the password reset interface.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1346">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/h:sun:sun_fire:x2100m2"/>
        <cpe-lang:fact-ref name="cpe:/h:sun:sun_fire:x2200m2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:sun:sun_fire:x2100m2</vuln:product>
      <vuln:product>cpe:/h:sun:sun_fire:x2200m2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1346</vuln:cve-id>
    <vuln:published-datetime>2007-03-08T17:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:51:58.393-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102828-1" xml:lang="en">102828</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22859" xml:lang="en">22859</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017738" xml:lang="en">1017738</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0869" xml:lang="en">ADV-2007-0869</vuln:reference>
    </vuln:references>
    <vuln:summary>Unspecified vulnerability in ipmitool for Sun Fire X2100M2 and X2200M2 allows local users to gain privileges and reset or turn off the server.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1347">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000::sp4::fr"/>
          <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_xp::sp2::fr"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:microsoft:windows_explorer"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:windows_explorer</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1347</vuln:cve-id>
    <vuln:published-datetime>2007-03-08T17:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:49.673-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://lostmon.blogspot.com/2007/08/windows-extended-file-attributes-buffer.html" xml:lang="en">http://lostmon.blogspot.com/2007/08/windows-extended-file-attributes-buffer.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/194944" xml:lang="en">VU#194944</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22847" xml:lang="en">22847</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017736" xml:lang="en">1017736</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EXPLOIT-DB</vuln:source>
      <vuln:reference href="https://www.exploit-db.com/exploits/3419" xml:lang="en">3419</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Windows Explorer on Windows 2000 SP4 FR and XP SP2 FR, and possibly other versions and platforms, allows remote attackers to cause a denial of service (memory corruption and crash) via an Office file with crafted document summary information, which causes an error in Ole32.dll.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1348">
    <vuln:cve-id>CVE-2007-1348</vuln:cve-id>
    <vuln:published-datetime>2018-02-23T11:29:00.203-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-02-23T11:29:00.237-05:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not a security issue.  Notes: none.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1349">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apache:apache_test:1.29"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_perl:2.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_perl:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_perl:2.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:mod_perl:2.0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:apache_test:1.29</vuln:product>
      <vuln:product>cpe:/a:apache:http_server</vuln:product>
      <vuln:product>cpe:/a:apache:mod_perl:2.0.0</vuln:product>
      <vuln:product>cpe:/a:apache:mod_perl:2.0.1</vuln:product>
      <vuln:product>cpe:/a:apache:mod_perl:2.0.2</vuln:product>
      <vuln:product>cpe:/a:apache:mod_perl:2.0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1349</vuln:cve-id>
    <vuln:published-datetime>2007-03-29T20:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:49.753-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>4.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10987" name="oval:org.mitre.oval:def:10987"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8349" name="oval:org.mitre.oval:def:8349"/>
    <vuln:cwe id="CWE-399"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.asc" xml:lang="en">20070602-01-P</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2007-0395.html" xml:lang="en">RHSA-2007:0395</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2008-0630.html" xml:lang="en">RHSA-2008:0630</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200705-04.xml" xml:lang="en">GLSA-200705-04</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-248386-1" xml:lang="en">248386</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021508.1-1" xml:lang="en">1021508</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2007-293.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2007-293.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://svn.apache.org/repos/asf/perl/modperl/branches/1.x/Changes" xml:lang="en">http://svn.apache.org/repos/asf/perl/modperl/branches/1.x/Changes</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.gossamer-threads.com/lists/modperl/modperl/92739" xml:lang="en">http://www.gossamer-threads.com/lists/modperl/modperl/92739</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:083" xml:lang="en">MDKSA-2007:083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_12_sr.html" xml:lang="en">SUSE-SR:2007:012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_8_sr.html" xml:lang="en">SUSE-SR:2007:008</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0396.html" xml:lang="en">RHSA-2007:0396</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0486.html" xml:lang="en">RHSA-2007:0486</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0261.html" xml:lang="en">RHSA-2008:0261</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2008-0627.html" xml:lang="en">RHSA-2008:0627</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23192" xml:lang="en">23192</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1018259" xml:lang="en">1018259</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-488-1" xml:lang="en">USN-488-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1150" xml:lang="en">ADV-2007-1150</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33312" xml:lang="en">modperl-pathinfo-dos(33312)</vuln:reference>
    </vuln:references>
    <vuln:summary>PerlRun.pm in Apache mod_perl before 1.30, and RegistryCooker.pm in mod_perl 2.x, does not properly escape PATH_INFO before use in a regular expression, which allows remote attackers to cause a denial of service (resource consumption) via a crafted URI.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1350">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:novell:netmail:3.5.2:a"/>
        <cpe-lang:fact-ref name="cpe:/a:novell:netmail:3.5.2:b"/>
        <cpe-lang:fact-ref name="cpe:/a:novell:netmail:3.5.2:c"/>
        <cpe-lang:fact-ref name="cpe:/a:novell:netmail:3.5.2:c1"/>
        <cpe-lang:fact-ref name="cpe:/a:novell:netmail:3.5.2:d"/>
        <cpe-lang:fact-ref name="cpe:/a:novell:netmail:3.5.2:e-ftfl"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:novell:netmail:3.5.2:a</vuln:product>
      <vuln:product>cpe:/a:novell:netmail:3.5.2:b</vuln:product>
      <vuln:product>cpe:/a:novell:netmail:3.5.2:c</vuln:product>
      <vuln:product>cpe:/a:novell:netmail:3.5.2:c1</vuln:product>
      <vuln:product>cpe:/a:novell:netmail:3.5.2:d</vuln:product>
      <vuln:product>cpe:/a:novell:netmail:3.5.2:e-ftfl</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1350</vuln:cve-id>
    <vuln:published-datetime>2007-03-08T17:19:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:38:01.220-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://download.novell.com/Download?buildid=sMYRODW09pw" xml:lang="en">http://download.novell.com/Download?buildid=sMYRODW09pw</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SREASON</vuln:source>
      <vuln:reference href="http://securityreason.com/securityalert/2395" xml:lang="en">2395</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/919369" xml:lang="en">VU#919369</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/462154/100/0/threaded" xml:lang="en">20070307 ZDI-07-009: Novell Netmail WebAdmin Buffer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/22857" xml:lang="en">22857</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017734" xml:lang="en">1017734</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/0870" xml:lang="en">ADV-2007-0870</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.zerodayinitiative.com/advisories/ZDI-07-009.html" xml:lang="en">http://www.zerodayinitiative.com/advisories/ZDI-07-009.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/32861" xml:lang="en">netmail-sprintf-bo(32861)</vuln:reference>
    </vuln:references>
    <vuln:summary>Stack-based buffer overflow in webadmin.exe in Novell NetMail 3.5.2 allows remote attackers to execute arbitrary code via a long username during HTTP Basic authentication.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1351">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:5.10::amd64"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:5.10::i386"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:5.10::powerpc"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:5.10::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:6.06_lts::amd64"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:6.06_lts::i386"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:6.06_lts::powerpc"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:6.06_lts::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:6.10::amd64"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:6.10::i386"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:6.10::powerpc"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:6.10::sparc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:x.org:libxfont:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.3.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:4.3.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:rpath:rpath_linux:1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::advanced_server_ia64"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::enterprise_server_ia64"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::workstation_ia64"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::advanced_servers"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:5.0::desktop"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:5.0::desktop_workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:5.0::server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_desktop:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_desktop:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux_advanced_workstation:2.1::ia64"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux_advanced_workstation:2.1::itanium"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:2007"/>
          <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:2007::x86_64"/>
          <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0"/>
          <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0::x86_64"/>
          <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0"/>
          <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0::x86_64"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:mandrakesoft:mandrake_multi_network_firewall:2.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mandrakesoft:mandrake_multi_network_firewall:2.0</vuln:product>
      <vuln:product>cpe:/a:x.org:libxfont:1.2.2</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.3.0</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.3.0.1</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:4.3.0.2</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.9</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:4.0</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::advanced_server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::advanced_server_ia64</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::enterprise_server_ia64</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::workstation</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::workstation_ia64</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::advanced_servers</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::workstation</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::advanced_server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::workstation</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:5.0::desktop</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:5.0::desktop_workstation</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:5.0::server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux_desktop:3.0</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux_desktop:4.0</vuln:product>
      <vuln:product>cpe:/o:redhat:linux_advanced_workstation:2.1::ia64</vuln:product>
      <vuln:product>cpe:/o:redhat:linux_advanced_workstation:2.1::itanium</vuln:product>
      <vuln:product>cpe:/o:rpath:rpath_linux:1</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:5.10::amd64</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:5.10::i386</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:5.10::powerpc</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:5.10::sparc</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:6.06_lts::amd64</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:6.06_lts::i386</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:6.06_lts::powerpc</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:6.06_lts::sparc</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:6.10::amd64</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:6.10::i386</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:6.10::powerpc</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:6.10::sparc</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1351</vuln:cve-id>
    <vuln:published-datetime>2007-04-05T21:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:38:01.957-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>8.5</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11266" name="oval:org.mitre.oval:def:11266"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1810" name="oval:org.mitre.oval:def:1810"/>
    <vuln:cwe id="CWE-189"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://issues.foresightlinux.org/browse/FL-223" xml:lang="en">http://issues.foresightlinux.org/browse/FL-223</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=501" xml:lang="en">20070403 Multiple Vendor X Server BDF Font Parsing Integer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Nov/msg00003.html" xml:lang="en">APPLE-SA-2007-11-14</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" xml:lang="en">APPLE-SA-2009-02-12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.freedesktop.org/archives/xorg-announce/2007-April/000286.html" xml:lang="en">[xorg-announce] 20070403 various integer overflow vulnerabilites in xserver, libX11 and libXfont</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2007-0125.html" xml:lang="en">RHSA-2007:0125</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200705-02.xml" xml:lang="en">GLSA-200705-02</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200705-10.xml" xml:lang="en">GLSA-200705-10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SLACKWARE</vuln:source>
      <vuln:reference href="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.626733" xml:lang="en">SSA:2007-109-01</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?group_id=3157&amp;release_id=498954" xml:lang="en">http://sourceforge.net/project/shownotes.php?group_id=3157&amp;release_id=498954</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sourceforge.net/project/shownotes.php?release_id=498954" xml:lang="en">http://sourceforge.net/project/shownotes.php?release_id=498954</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102886-1" xml:lang="en">102886</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3438" xml:lang="en">http://support.apple.com/kb/HT3438</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2007-178.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2007-178.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2007-193.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2007-193.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1294" xml:lang="en">DSA-1294</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2008/dsa-1454" xml:lang="en">DSA-1454</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://www.gentoo.org/security/en/glsa/glsa-200805-07.xml" xml:lang="en">GLSA-200805-07</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:079" xml:lang="en">MDKSA-2007:079</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:080" xml:lang="en">MDKSA-2007:080</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:081" xml:lang="en">MDKSA-2007:081</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_27_x.html" xml:lang="en">SUSE-SA:2007:027</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_6_sr.html" xml:lang="en">SUSE-SR:2007:006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OPENBSD</vuln:source>
      <vuln:reference href="http://www.openbsd.org/errata39.html#021_xorg" xml:lang="en">[3.9] 021: SECURITY FIX: April 4, 2007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OPENBSD</vuln:source>
      <vuln:reference href="http://www.openbsd.org/errata40.html#011_xorg" xml:lang="en">[4.0] 011: SECURITY FIX: April 4, 2007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0126.html" xml:lang="en">RHSA-2007:0126</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0132.html" xml:lang="en">RHSA-2007:0132</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0150.html" xml:lang="en">RHSA-2007:0150</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/464686/100/0/threaded" xml:lang="en">20070404 rPSA-2007-0065-1 freetype xorg-x11 xorg-x11-fonts xorg-x11-tools xorg-x11-xfs</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/464816/100/0/threaded" xml:lang="en">20070405 FLEA-2007-0009-1: xorg-x11 freetype</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23283" xml:lang="en">23283</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23300" xml:lang="en">23300</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23402" xml:lang="en">23402</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017857" xml:lang="en">1017857</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>TRUSTIX</vuln:source>
      <vuln:reference href="http://www.trustix.org/errata/2007/0013/" xml:lang="en">2007-0013</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-448-1" xml:lang="en">USN-448-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1217" xml:lang="en">ADV-2007-1217</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1264" xml:lang="en">ADV-2007-1264</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1548" xml:lang="en">ADV-2007-1548</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33417" xml:lang="en">xorg-bdf-font-bo(33417)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1213" xml:lang="en">https://issues.rpath.com/browse/RPL-1213</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remote authenticated users to execute arbitrary code via crafted BDF fonts, which result in a heap overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1352">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="AND" negate="false">
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:9.1"/>
          <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:9.1::ppc"/>
          <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:9.2"/>
          <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:9.2::amd64"/>
          <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:10.0"/>
          <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:10.0::amd64"/>
          <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:2007"/>
          <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux:2007::x86_64"/>
          <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0"/>
          <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0::x86_64"/>
          <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0"/>
          <cpe-lang:fact-ref name="cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0::x86_64"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test operator="OR" negate="false">
          <cpe-lang:fact-ref name="cpe:/a:mandrakesoft:mandrake_multi_network_firewall:2.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:x.org:libxfont:1.2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::advanced_server_ia64"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::enterprise_server_ia64"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:2.1::workstation_ia64"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:3.0::workstation_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::advanced_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::enterprise_server"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux:4.0::workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_desktop:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_desktop:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_desktop:5.0::client"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:enterprise_linux_desktop:5.0::client_workstation"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:fedora_core:core_1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:9.0::i386"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux_advanced_workstation:2.1::ia64"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux_advanced_workstation:2.1::itanium"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:9.0"/>
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:9.1"/>
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:current"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:turbolinux:turbolinux_desktop:10.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:4.1::ia32"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:4.1::ia64"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:4.1::ppc"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:5.10::amd64"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:5.10::i386"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:5.10::powerpc"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:5.10::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:6.06_lts::amd64"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:6.06_lts::i386"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:6.06_lts::powerpc"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:6.06_lts::sparc"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:6.10::amd64"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:6.10::i386"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:6.10::powerpc"/>
        <cpe-lang:fact-ref name="cpe:/o:ubuntu:ubuntu_linux:6.10::sparc"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:rpath:linux:1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mandrakesoft:mandrake_multi_network_firewall:2.0</vuln:product>
      <vuln:product>cpe:/a:x.org:libxfont:1.2.2</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:3.9</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:4.0</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::advanced_server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::advanced_server_ia64</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::enterprise_server_ia64</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::workstation</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:2.1::workstation_ia64</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::advanced_server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:3.0::workstation_server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::advanced_server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::enterprise_server</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux:4.0::workstation</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux_desktop:3.0</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux_desktop:4.0</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux_desktop:5.0::client</vuln:product>
      <vuln:product>cpe:/o:redhat:enterprise_linux_desktop:5.0::client_workstation</vuln:product>
      <vuln:product>cpe:/o:redhat:fedora_core:core_1.0</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:9.0::i386</vuln:product>
      <vuln:product>cpe:/o:redhat:linux_advanced_workstation:2.1::ia64</vuln:product>
      <vuln:product>cpe:/o:redhat:linux_advanced_workstation:2.1::itanium</vuln:product>
      <vuln:product>cpe:/o:rpath:linux:1</vuln:product>
      <vuln:product>cpe:/o:slackware:slackware_linux:9.0</vuln:product>
      <vuln:product>cpe:/o:slackware:slackware_linux:9.1</vuln:product>
      <vuln:product>cpe:/o:slackware:slackware_linux:current</vuln:product>
      <vuln:product>cpe:/o:turbolinux:turbolinux_desktop:10.0</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:4.1::ia32</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:4.1::ia64</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:4.1::ppc</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:5.10::amd64</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:5.10::i386</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:5.10::powerpc</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:5.10::sparc</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:6.06_lts::amd64</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:6.06_lts::i386</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:6.06_lts::powerpc</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:6.06_lts::sparc</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:6.10::amd64</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:6.10::i386</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:6.10::powerpc</vuln:product>
      <vuln:product>cpe:/o:ubuntu:ubuntu_linux:6.10::sparc</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1352</vuln:cve-id>
    <vuln:published-datetime>2007-04-05T21:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2018-10-16T12:38:09.313-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>3.8</cvss:score>
        <cvss:access-vector>ADJACENT_NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10523" name="oval:org.mitre.oval:def:10523"/>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13243" name="oval:org.mitre.oval:def:13243"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://issues.foresightlinux.org/browse/FL-223" xml:lang="en">http://issues.foresightlinux.org/browse/FL-223</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>IDEFENSE</vuln:source>
      <vuln:reference href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=502" xml:lang="en">20070403 Multiple Vendor X Server fonts.dir File Parsing Integer Overflow Vulnerability</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/Security-announce/2007/Nov/msg00003.html" xml:lang="en">APPLE-SA-2007-11-14</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>APPLE</vuln:source>
      <vuln:reference href="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" xml:lang="en">APPLE-SA-2009-02-12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://lists.freedesktop.org/archives/xorg-announce/2007-April/000286.html" xml:lang="en">[xorg-announce] 20070403 various integer overflow vulnerabilites in xserver, libX11 and libXfont</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2007-0125.html" xml:lang="en">RHSA-2007:0125</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>GENTOO</vuln:source>
      <vuln:reference href="http://security.gentoo.org/glsa/glsa-200705-10.xml" xml:lang="en">GLSA-200705-10</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUNALERT</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102886-1" xml:lang="en">102886</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.apple.com/kb/HT3438" xml:lang="en">http://support.apple.com/kb/HT3438</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2007-178.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2007-178.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1294" xml:lang="en">DSA-1294</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:079" xml:lang="en">MDKSA-2007:079</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MANDRIVA</vuln:source>
      <vuln:reference href="http://www.mandriva.com/security/advisories?name=MDKSA-2007:080" xml:lang="en">MDKSA-2007:080</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_27_x.html" xml:lang="en">SUSE-SA:2007:027</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OPENBSD</vuln:source>
      <vuln:reference href="http://www.openbsd.org/errata39.html#021_xorg" xml:lang="en">[3.9] 021: SECURITY FIX: April 4, 2007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OPENBSD</vuln:source>
      <vuln:reference href="http://www.openbsd.org/errata40.html#011_xorg" xml:lang="en">[4.0] 011: SECURITY FIX: April 4, 2007</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0126.html" xml:lang="en">RHSA-2007:0126</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0132.html" xml:lang="en">RHSA-2007:0132</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/464686/100/0/threaded" xml:lang="en">20070404 rPSA-2007-0065-1 freetype xorg-x11 xorg-x11-fonts xorg-x11-tools xorg-x11-xfs</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/464816/100/0/threaded" xml:lang="en">20070405 FLEA-2007-0009-1: xorg-x11 freetype</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23283" xml:lang="en">23283</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23300" xml:lang="en">23300</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SECTRACK</vuln:source>
      <vuln:reference href="http://www.securitytracker.com/id?1017857" xml:lang="en">1017857</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-448-1" xml:lang="en">USN-448-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1217" xml:lang="en">ADV-2007-1217</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1548" xml:lang="en">ADV-2007-1548</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="https://exchange.xforce.ibmcloud.com/vulnerabilities/33419" xml:lang="en">xorg-fontsdir-bo(33419)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="https://issues.rpath.com/browse/RPL-1213" xml:lang="en">https://issues.rpath.com/browse/RPL-1213</vuln:reference>
    </vuln:references>
    <vuln:summary>Integer overflow in the FontFileInitTable function in X.Org libXfont before 20070403 allows remote authenticated users to execute arbitrary code via a long first line in the fonts.dir file, which results in a heap overflow.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1353">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.4.34.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.4.34.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1353</vuln:cve-id>
    <vuln:published-datetime>2007-04-24T12:19:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2017-10-10T21:31:50.110-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check system="http://oval.mitre.org/XMLSchema/oval-definitions-5" href="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10626" name="oval:org.mitre.oval:def:10626"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2007-0488.html" xml:lang="en">RHSA-2007:0488</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2007-287.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2007-287.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.avaya.com/elmodocs2/security/ASA-2007-404.htm" xml:lang="en">http://support.avaya.com/elmodocs2/security/ASA-2007-404.htm</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2007/dsa-1356" xml:lang="en">DSA-1356</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2008/dsa-1503" xml:lang="en">DSA-1503</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>DEBIAN</vuln:source>
      <vuln:reference href="http://www.debian.org/security/2008/dsa-1504" xml:lang="en">DSA-1504</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.34.3" xml:lang="en">http://www.kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.34.3</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUSE</vuln:source>
      <vuln:reference href="http://www.novell.com/linux/security/advisories/2007_35_kernel.html" xml:lang="en">SUSE-SA:2007:035</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0671.html" xml:lang="en">RHSA-2007:0671</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0672.html" xml:lang="en">RHSA-2007:0672</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://www.redhat.com/support/errata/RHSA-2007-0673.html" xml:lang="en">RHSA-2007:0673</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/23594" xml:lang="en">23594</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-470-1" xml:lang="en">USN-470-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-486-1" xml:lang="en">USN-486-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>UBUNTU</vuln:source>
      <vuln:reference href="http://www.ubuntu.com/usn/usn-489-1" xml:lang="en">USN-489-1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>VUPEN</vuln:source>
      <vuln:reference href="http://www.vupen.com/english/advisories/2007/1495" xml:lang="en">ADV-2007-1495</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="https://rhn.redhat.com/errata/RHSA-2007-0376.html" xml:lang="en">RHSA-2007:0376</vuln:reference>
    </vuln:references>
    <vuln:summary>The setsockopt function in the L2CAP and HCI Bluetooth support in the Linux kernel before 2.4.34.3 allows context-dependent attackers to read kernel memory and obtain sensitive information via unspecified vectors involving the copy_from_user function accessing an uninitialized stack buffer.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1354">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:jboss:jboss_application_server:4.0.2.ga_cp02"/>
        <cpe-lang:fact-ref name="cpe:/a:jboss:jboss_application_server:4.0.2.ga_cp03"/>
        <cpe-lang:fact-ref name="cpe:/a:jboss:jboss_application_server:4.0.2.ga_cp04"/>
        <cpe-lang:fact-ref name="cpe:/a:jboss:jboss_application_server:4.0.5.ga"/>
        <cpe-lang:fact-ref name="cpe:/a:jboss:jboss_application_server:4.0.5_cp01"/>
        <cpe-lang:fact-ref name="cpe:/a:jboss:jboss_application_server:4.0.5_cp02"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:jboss:jboss_application_server:4.0.2.ga_cp02</vuln:product>
      <vuln:product>cpe:/a:jboss:jboss_application_server:4.0.2.ga_cp03</vuln:product>
      <vuln:product>cpe:/a:jboss:jboss_application_server:4.0.2.ga_cp04</vuln:product>
      <vuln:product>cpe:/a:jboss:jboss_application_server:4.0.5.ga</vuln:product>
      <vuln:product>cpe:/a:jboss:jboss_application_server:4.0.5_cp01</vuln:product>
      <vuln:product>cpe:/a:jboss:jboss_application_server:4.0.5_cp02</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-2007-1354</vuln:cve-id>
    <vuln:published-datetime>2007-07-27T17:30:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-11-13T01:34:42.910-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>SINGLE_INSTANCE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://jira.jboss.com/jira/browse/ASPATCH-172" xml:lang="en">http://jira.jboss.com/jira/browse/ASPATCH-172</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://jira.jboss.com/jira/browse/ASPATCH-175" xml:lang="en">http://jira.jboss.com/jira/browse/ASPATCH-175</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>REDHAT</vuln:source>
      <vuln:reference href="http://rhn.redhat.com/errata/RHSA-2007-0151.html" xml:lang="en">RHSA-2007:0151</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>MLIST</vuln:source>
      <vuln:reference href="http://www.redhat.com/archives/jboss-watch-list/2007-April/msg00000.html" xml:lang="en">[jboss-watch-list] 20070416 [RHSA-2007:0151-01] Low: JBoss Application Server security update</vuln:reference>
    </vuln:references>
    <vuln:summary>The Access Control functionality (JMXOpsAccessControlFilter) in JMX Console in JBoss Application Server 4.0.2 and 4.0.5 before 20070416 uses a member variable to store the roles of the current user, which allows remote authenticated administrators to trigger a race condition and gain privileges by logging in during a session by a more privileged administrator, as demonstrated by privilege escalation from Read Mode to Write Mode.</vuln:summary>
  </entry>
  <entry id="CVE-2007-1355">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.10"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.15"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.24"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.28"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:4.1.31"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.10"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.11"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.12"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.13"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.14"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.15"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.16"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.17"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.18"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.19"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.21"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.22"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.23"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.24"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.25"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.26"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.27"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.28"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.29"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:5.0.30"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.4"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.6"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.7"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.8"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:tomcat:6.0.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:tomcat:4.0.0</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.0.1</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.0.2</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.0.3</vuln:product>
      <vuln:product>cpe:/a:apache:tomcat:4.0.4</vuln:product>
      <vuln:product>cpe:/a:apa